VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 169 of 213
  • CVE-2022-3585MedOct 18, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability classified as problematic has been found in SourceCodester Simple Cold Storage Management System 1.0. Affected is an unknown function of the file /csms/?page=contact_us of the component Contact Us. The manipulation leads to cross-site request forgery. It is…

  • CVE-2022-3582MedOct 18, 2022
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Simple Cold Storage Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument change password leads to cross-site request forgery. The attack…

  • CVE-2022-42724MedOct 10, 2022
    risk 0.28cvss 4.3epss 0.00

    app/Controller/UsersController.php in MISP before 2.4.164 allows attackers to discover role names (this is information that only the site admin should have).

  • CVE-2021-40692MedSep 29, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient capability checks made it possible for teachers to download users outside of their courses.

  • CVE-2022-36109MedSep 9, 2022
    risk 0.28cvss 5.3epss 0.01

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access,…

  • CVE-2021-3763MedAug 23, 2022
    risk 0.28cvss 4.3epss 0.01

    A flaw was found in the Red Hat AMQ Broker management console in version 7.8 where an existing user is able to access some limited information even when the role the user is assigned to should not be allow access to the management console. The main impact is to confidentiality…

  • CVE-2022-2095MedAug 5, 2022
    risk 0.28cvss 4.3epss 0.01

    An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to view a public project's Deploy Key's…

  • CVE-2022-31190MedAug 1, 2022
    risk 0.28cvss 5.3epss 0.01

    DSpace open source software is a repository application which provides durable access to digital resources. dspace-xmlui is a UI component for DSpace. In affected versions metadata on a withdrawn Item is exposed via the XMLUI "mets.xml" object, as long as you know the handle/URL…

  • CVE-2022-31178MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.00

    eLabFTW is an electronic lab notebook manager for research teams. A vulnerability was discovered which allows a logged in user to read a template without being authorized to do so. This vulnerability has been patched in 4.3.4. Users are advised to upgrade. There are no known…

  • CVE-2022-31155MedAug 1, 2022
    risk 0.28cvss 4.3epss 0.00

    Sourcegraph is an opensource code search and navigation engine. In Sourcegraph versions before 3.41.0, it is possible for an attacker to delete other users’ saved searches due to a bug in the authorization check. The vulnerability does not allow the reading of other users’…

  • CVE-2022-2408MedJul 14, 2022
    risk 0.28cvss 4.3epss 0.01

    The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.

  • CVE-2022-32290MedJul 6, 2022
    risk 0.28cvss 4.3epss 0.00

    The client in Northern.tech Mender 3.2.0, 3.2.1, and 3.2.2 has Incorrect Access Control. It listens on a random, unprivileged TCP port and exposes an HTTP proxy to facilitate API calls from additional client components running on the device. However, it listens on all network…

  • CVE-2022-34814MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins Request Rename Or Delete Plugin 1.1.0 and earlier does not correctly perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to view an administrative configuration page listing pending requests.

  • CVE-2022-34785MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.

  • CVE-2022-34782MedJun 30, 2022
    risk 0.28cvss 4.3epss 0.01

    An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.

  • CVE-2022-34298MedJun 23, 2022
    risk 0.28cvss 5.3epss 0.03

    The NT auth module in OpenAM before 14.6.6 allows a "replace Samba username attack."

  • CVE-2021-3956MedMay 18, 2022
    risk 0.28cvss 4.3epss 0.01

    A read-only authentication bypass vulnerability was reported in the Third Quarter 2021 release of Lenovo XClarity Controller (XCC) firmware affecting XCC devices configured in LDAP Authentication Only Mode and using an LDAP server that supports “unauthenticated bind”, such…

  • CVE-2022-1417MedMay 10, 2022
    risk 0.28cvss 4.3epss 0.01

    Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access contents of Project Members-only Wikis via…

  • CVE-2022-29047MedApr 12, 2022
    risk 0.28cvss 5.3epss 0.01

    Jenkins Pipeline: Shared Groovy Libraries Plugin 564.ve62a_4eb_b_e039 and earlier, except 2.21.3, allows attackers able to submit pull requests (or equivalent), but not able to commit directly to the configured SCM, to effectively change the Pipeline behavior by changing the…

  • CVE-2022-0825MedApr 4, 2022
    risk 0.28cvss 5.4epss 0.01

    The Amelia WordPress plugin before 1.0.49 does not have proper authorisation when managing appointments, allowing any customer to update other's booking status, as well as retrieve sensitive information about the bookings, such as the full name and phone number of the person who…