CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,734)
page 183 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-4268 | Med | 0.00 | 4.3 | 0.00 | Dec 21, 2022 | A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this… | ||
| CVE-2022-4397 | Med | 0.00 | 4.3 | 0.00 | Dec 10, 2022 | A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to… | ||
| CVE-2022-41970 | Low | 0.00 | 2.6 | 0.01 | Dec 1, 2022 | Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.… | ||
| CVE-2022-41944 | Low | 0.00 | 3.5 | 0.00 | Nov 28, 2022 | Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the… | ||
| CVE-2022-39385 | Med | 0.00 | 6.5 | 0.01 | Nov 14, 2022 | Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This… | ||
| CVE-2022-39302 | Med | 0.00 | 5.5 | 0.00 | Oct 14, 2022 | Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and… | ||
| CVE-2022-39275 | Med | 0.00 | 5.3 | 0.01 | Oct 6, 2022 | Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose… | ||
| CVE-2022-36074 | Med | 0.00 | 6.4 | 0.01 | Sep 15, 2022 | Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that… | ||
| CVE-2022-31168 | Med | 0.00 | 5.4 | 0.01 | Jul 22, 2022 | Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server… | ||
| CVE-2022-31087 | Hig | 0.00 | 7.8 | 0.00 | Jun 27, 2022 | LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An… | ||
| CVE-2022-31039 | Med | 0.00 | 4.3 | 0.01 | Jun 27, 2022 | Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has… | ||
| CVE-2022-1706 | Med | 0.00 | 6.5 | 0.01 | May 17, 2022 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is… | ||
| CVE-2022-24865 | Med | 0.00 | 6.5 | 0.01 | Apr 20, 2022 | HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0,… | ||
| CVE-2022-24841 | Med | 0.00 | 6.5 | 0.01 | Apr 18, 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In… | ||
| CVE-2022-1224 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2022-1223 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2022-0406 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. | ||
| CVE-2022-24755 | Hig | 0.00 | 8.1 | 0.02 | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired… | ||
| CVE-2022-24128 | Hig | 0.00 | 8.0 | 0.01 | Mar 13, 2022 | Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer… |
- risk 0.00cvss 4.3epss 0.00
A vulnerability, which was classified as problematic, was found in phpRedisAdmin up to 1.17.3. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. Upgrading to version 1.18.0 is able to address this…
- risk 0.00cvss 4.3epss 0.00
A vulnerability was found in morontt zend-blog-number-2. It has been classified as problematic. Affected is an unknown function of the file application/forms/Comment.php of the component Comment Handler. The manipulation leads to cross-site request forgery. It is possible to…
- risk 0.00cvss 2.6epss 0.01
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.…
- risk 0.00cvss 3.5epss 0.00
Discourse is an open-source discussion platform. In stable versions prior to 2.8.12 and beta or tests-passed versions prior to 2.9.0.beta.13, under certain conditions, a user can see notifications for topics they no longer have access to. If there is sensitive information in the…
- risk 0.00cvss 6.5epss 0.01
Discourse is the an open source discussion platform. In some rare cases users redeeming an invitation can be added as a participant to several private message topics that they should not be added to. They are not notified of this, it happens transparently in the background. This…
- risk 0.00cvss 5.5epss 0.00
Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and…
- risk 0.00cvss 5.3epss 0.01
Saleor is a headless, GraphQL commerce platform. In affected versions some GraphQL mutations were not properly checking the ID type input which allowed to access database objects that the authenticated user may not be allowed to access. This vulnerability can be used to expose…
- risk 0.00cvss 6.4epss 0.01
Nextcloud server is an open source personal cloud product. Affected versions of this package are vulnerable to Information Exposure which fails to strip the Authorization header on HTTP downgrade. This can lead to account access exposure and compromise. It is recommended that…
- risk 0.00cvss 5.4epss 0.01
Zulip is an open source team chat tool. Due to an incorrect authorization check in Zulip Server 5.4 and earlier, a member of an organization could craft an API call that grants organization administrator privileges to one of their bots. The vulnerability is fixed in Zulip Server…
- risk 0.00cvss 7.8epss 0.00
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the tmp directory, which is accessible by /lam/tmp/, allows interpretation of .php (and .php5/.php4/.phpt/etc) files. An…
- risk 0.00cvss 4.3epss 0.01
Greenlight is a simple front-end interface for your BigBlueButton server. In affected versions an attacker can view any room's settings even though they are not authorized to do so. Only the room owner and administrator should be able to view a room's settings. This issue has…
- risk 0.00cvss 6.5epss 0.01
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…
- risk 0.00cvss 6.5epss 0.01
HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0,…
- risk 0.00cvss 6.5epss 0.01
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…
- risk 0.00cvss 6.5epss 0.01
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- risk 0.00cvss 6.5epss 0.01
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- risk 0.00cvss 4.3epss 0.01
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- risk 0.00cvss 8.1epss 0.02
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired…
- risk 0.00cvss 8.0epss 0.01
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…