VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,241)

page 170 of 213
  • CVE-2021-39876MedMar 28, 2022
    risk 0.28cvss 4.3epss 0.01

    In all versions of GitLab CE/EE since version 11.3, the endpoint for auto-completing Assignee discloses the members of private groups.

  • CVE-2021-41241MedMar 8, 2022
    risk 0.28cvss 4.3epss 0.01

    Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…

  • CVE-2021-24824MedMar 7, 2022
    risk 0.28cvss 4.3epss 0.01

    The [field] shortcode included with the Custom Content Shortcode WordPress plugin before 4.0.1, allows authenticated users with a role as low as contributor, to access arbitrary post metadata. This could lead to sensitive data disclosure, for example when used in combination…

  • CVE-2021-39943MedFeb 9, 2022
    risk 0.28cvss 4.3epss 0.01

    An authorization logic error in the External Status Check API in GitLab EE affecting all versions starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allowed a user to update the status of the check via…

  • CVE-2022-23615MedFeb 9, 2022
    risk 0.28cvss 5.4epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions any user with SCRIPT right can save a document with the right of the current user which allow accessing API requiring programming right if the current…

  • CVE-2021-24733MedJan 24, 2022
    risk 0.28cvss 4.3epss 0.01

    The WP Post Page Clone WordPress plugin before 1.2 allows users with a role as low as Contributor to clone and view other users' draft and password-protected posts which they cannot view normally.

  • CVE-2021-39930MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates

  • CVE-2021-24819MedDec 13, 2021
    risk 0.28cvss 4.3epss 0.01

    The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by…

  • CVE-2021-24851MedNov 17, 2021
    risk 0.28cvss 4.3epss 0.01

    The Insert Pages WordPress plugin before 3.7.0 allows users with a role as low as Contributor to access content and metadata from arbitrary posts/pages regardless of their author and status (ie private), using a shortcode. Password protected posts/pages are not affected by such…

  • CVE-2021-42026MedNov 9, 2021
    risk 0.28cvss 4.3epss 0.01

    A vulnerability has been identified in Mendix Applications using Mendix 8 (All versions < V8.18.13), Mendix Applications using Mendix 9 (All versions < V9.6.2). Applications built with affected versions of Mendix Studio Pro do not properly control read access for certain client…

  • CVE-2021-41230MedNov 5, 2021
    risk 0.28cvss 5.3epss 0.01

    Pomerium is an open source identity-aware access proxy. In affected versions changes to the OIDC claims of a user after initial login are not reflected in policy evaluation when using `allowed_idp_claims` as part of policy. If using `allowed_idp_claims` and a user's claims are…

  • CVE-2021-39904MedNov 5, 2021
    risk 0.28cvss 4.3epss 0.01

    An Improper Access Control vulnerability in the GraphQL API in all versions of GitLab CE/EE starting from 13.1 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 allows a Merge Request creator to resolve discussions…

  • CVE-2021-39902MedNov 4, 2021
    risk 0.28cvss 4.3epss 0.01

    Incorrect Authorization in GitLab CE/EE 13.4 or above allows a user with guest membership in a project to modify the severity of an incident.

  • CVE-2021-28661MedOct 7, 2021
    risk 0.28cvss 4.3epss 0.01

    Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

  • CVE-2021-1854MedSep 8, 2021
    risk 0.28cvss 4.3epss 0.01

    A call termination issue with was addressed with improved logic. This issue is fixed in iOS 14.5 and iPadOS 14.5. A legacy cellular network can automatically answer an incoming call when an ongoing call ends or drops. .

  • CVE-2021-22247MedAug 25, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics

  • CVE-2021-22251MedAug 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Improper validation of invited users' email address in GitLab EE affecting all versions since 12.2 allowed projects to add members with email address domain that should be blocked by group settings

  • CVE-2021-36383MedJul 12, 2021
    risk 0.28cvss 4.3epss 0.01

    Xen Orchestra (with xo-web through 5.80.0 and xo-server through 5.84.0) mishandles authorization, as demonstrated by modified WebSocket resourceSet.getAll data is which the attacker changes the permission field from none to admin. The attacker gains access to data sets such as…

  • CVE-2021-29961MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    When styling and rendering an oversized `` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.

  • CVE-2021-29959MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    When a user has already allowed a website to access microphone and camera, disabling camera sharing would not fully prevent the website from re-enabling it without an additional prompt. This was only possible if the website kept recording with the microphone until re-enabling…