VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 165 of 187
  • CVE-2024-4011LowJun 27, 2024
    risk 0.20cvss 3.1epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows non-project member to promote key results to objectives.

  • CVE-2024-23823MedMar 14, 2024
    risk 0.20cvss 4.2epss 0.00

    vantage6 is an open source framework built to enable, manage and deploy privacy enhancing technologies like Federated Learning and Multi-Party Computation. The vantage6 server has no restrictions on CORS settings. It should be possible for people to set the allowed origins of…

  • CVE-2023-4658LowDec 1, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 8.13 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for an attacker to abuse the `Allowed to merge` permission as a guest…

  • CVE-2023-3443LowDec 1, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 12.1 before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. It was possible for a Guest user to add an emoji on confidential work items.

  • CVE-2023-3979LowSep 29, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 10.6 before 16.2.8, all versions starting from 16.3 before 16.3.5, all versions starting from 16.4 before 16.4.1. It was possible that upstream members to collaborate with you on your branch get…

  • CVE-2023-23476LowAug 2, 2023
    risk 0.20cvss 3.1epss 0.00

    IBM Robotic Process Automation 21.0.0 through 21.0.7.latest is vulnerable to unauthorized access to data due to insufficient authorization validation on some API routes. IBM X-Force ID: 245425.

  • CVE-2023-3590LowJul 17, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to delete card attachments in Boards, allowing an attacker to access deleted attachments.

  • CVE-2023-3584LowJul 17, 2023
    risk 0.20cvss 3.1epss 0.00

    Mattermost fails to properly check the authorization of POST /api/v4/teams when passing a team override scheme ID in the request, allowing an authenticated attacker with knowledge of a Team Override Scheme ID to create a new team with said team override scheme.

  • CVE-2023-27525LowApr 17, 2023
    risk 0.20cvss 3.1epss 0.01

    An authenticated user with Gamma role authorization could have access to metadata information using non trivial methods in Apache Superset up to and including 2.0.1

  • CVE-2023-1071LowApr 5, 2023
    risk 0.20cvss 3.1epss 0.00

    An issue has been discovered in GitLab affecting all versions from 15.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1. Due to improper permissions checks it was possible for an unauthorised user to remove an issue…

  • CVE-2023-27594MedMar 17, 2023
    risk 0.20cvss 4.2epss 0.01

    Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.11.15, 1.12.8, and 1.13.1, under specific conditions, Cilium may misattribute the source IP address of traffic to a cluster, identifying external traffic as coming from…

  • CVE-2022-0740LowApr 4, 2022
    risk 0.20cvss 3.1epss 0.01

    Incorrect authorization in the Asana integration's branch restriction feature in all versions of GitLab CE/EE starting from version 7.8.0 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 makes it possible to close Asana…

  • CVE-2021-39918LowDec 13, 2021
    risk 0.20cvss 3.1epss 0.01

    Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.

  • CVE-2021-43553LowNov 17, 2021
    risk 0.20cvss 3.1epss 0.01

    PI Vision could disclose information to a user with insufficient privileges for an AF attribute that is the child of another attribute and is configured as a Limits property.

  • CVE-2021-22211LowMay 6, 2021
    risk 0.20cvss 3.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7. GitLab Dependency Proxy, under certain circumstances, can impersonate a user resulting in possibly incorrect access handling.

  • CVE-2018-15754MedDec 13, 2018
    risk 0.20cvss 4.2epss 0.02

    Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be…

  • CVE-2024-47157LowDec 26, 2024
    risk 0.19cvss 2.9epss 0.00

    Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions.

  • CVE-2021-3493HigKEVApr 17, 2021
    risk 0.19cvss 8.8epss 0.49

    The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting of file capabilities on files in an underlying file system. Due to the combination of unprivileged user namespaces along with a patch carried in the Ubuntu…

  • CVE-2020-15248MedNov 23, 2020
    risk 0.19cvss 4.0epss 0.00

    October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.470, backend users with the default "Publisher" system role have access to create & manage users where they can choose which…

  • CVE-2026-48412LowAug 11, 2026
    risk 0.18cvss 2.7epss 0.00

    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker with high privileges could exploit this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user…