VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 162 of 187
  • CVE-2022-20558LowDec 16, 2022
    risk 0.21cvss 3.3epss 0.00

    In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…

  • CVE-2022-3978MedNov 13, 2022
    risk 0.21cvss 4.3epss 0.00

    A vulnerability, which was classified as problematic, was found in NodeBB up to 2.5.7. This affects an unknown part of the file /register/abort. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 2.5.8 is…

  • CVE-2022-41230MedSep 21, 2022
    risk 0.21cvss 4.3epss 0.01

    Jenkins Build-Publisher Plugin 1.22 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to obtain names and URLs of Jenkins servers that the plugin is configured to publish builds to, as well as builds pending for…

  • CVE-2022-22326LowAug 1, 2022
    risk 0.21cvss 3.3epss 0.00

    IBM Datapower Gateway 10.0.2.0 through 10.0.4.0, 10.0.1.0 through 10.0.1.5, and 2018.4.1.0 through 2018.4.1.18 could allow unauthorized viewing of logs and files due to insufficient authorization checks. IBM X-Force ID: 218856.

  • CVE-2022-1124MedMay 11, 2022
    risk 0.21cvss 4.3epss 0.01

    An improper authorization issue has been discovered in GitLab CE/EE affecting all versions prior to 14.8.6, all versions from 14.9.0 prior to 14.9.4, and 14.10.0, allowing Guest project members to access trace log of jobs when it is enabled

  • CVE-2022-0984MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.

  • CVE-2022-0985MedApr 29, 2022
    risk 0.21cvss 4.3epss 0.01

    Insufficient capability checks could allow users with the moodle/site:uploadusers capability to delete users, without having the necessary moodle/user:delete capability.

  • CVE-2022-27575LowApr 11, 2022
    risk 0.21cvss 3.3epss 0.00

    Information exposure vulnerability in One UI Home prior to SMR April-2022 Release 1 allows to access currently launched foreground app information without permission.

  • CVE-2022-1193MedApr 11, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper access control in GitLab CE/EE versions 10.7 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allows a malicious actor to obtain details of the latest commit in a private project via Merge Requests under certain circumstances

  • CVE-2022-0334MedJan 25, 2022
    risk 0.21cvss 4.3epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. Insufficient capability checks could lead to users accessing their grade report for courses where they did not have the required gradereport/user:view…

  • CVE-2021-4026MedNov 30, 2021
    risk 0.21cvss 4.3epss 0.01

    bookstack is vulnerable to Improper Access Control

  • CVE-2021-25954MedAug 9, 2021
    risk 0.21cvss 4.3epss 0.01

    In “Dolibarr” application, 2.8.1 to 13.0.4 don’t restrict or incorrectly restricts access to a resource from an unauthorized actor. A low privileged attacker can modify the Private Note which only an administrator has rights to do, the affected field is at…

  • CVE-2021-21670MedJun 30, 2021
    risk 0.21cvss 4.3epss 0.02

    Jenkins 2.299 and earlier, LTS 2.289.1 and earlier allows users to cancel queue items and abort builds of jobs for which they have Item/Cancel permission even when they do not have Item/Read permission.

  • CVE-2021-21624MedMar 18, 2021
    risk 0.21cvss 4.3epss 0.01

    An incorrect permission check in Jenkins Role-based Authorization Strategy Plugin 3.1 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.

  • CVE-2021-20283MedMar 15, 2021
    risk 0.21cvss 4.3epss 0.01

    The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.

  • CVE-2020-29605MedJan 29, 2021
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in MantisBT before 2.24.4. Due to insufficient access-level checks, any logged-in user allowed to perform Group Actions can get access to the Summary fields of private Issues via bug_arr[]= in a crafted bug_actiongroup_page.php URL. (The target Issues can…

  • CVE-2020-0481LowDec 15, 2020
    risk 0.21cvss 3.3epss 0.00

    In AndroidManifest.xml, there is a possible permissions bypass. This could lead to local escalation of privilege allowing a non-system app to send a broadcast it shouldn't have permissions to send, with no additional execution privileges needed. User interaction is not needed…

  • CVE-2020-25781MedSep 30, 2020
    risk 0.21cvss 4.3epss 0.01

    An issue was discovered in file_download.php in MantisBT before 2.24.3. Users without access to view private issue notes are able to download the (supposedly private) attachments linked to these notes by accessing the corresponding file download URL directly.

  • CVE-2020-2258MedSep 16, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Health Advisor by CloudBees Plugin 3.2.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view that HTTP endpoint.

  • CVE-2020-25026MedSep 2, 2020
    risk 0.21cvss 4.3epss 0.01

    The sf_event_mgt (aka Event management and registration) extension before 4.3.1 and 5.x before 5.1.1 for TYPO3 allows Information Disclosure (participant data, and event data via email) because of Broken Access Control.