VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,734)

page 184 of 187
  • CVE-2021-41233MedMar 10, 2022
    risk 0.00cvss 6.5epss 0.01

    Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful…

  • CVE-2022-24714MedMar 8, 2022
    risk 0.00cvss 5.3epss 0.01

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with…

  • CVE-2021-41241MedMar 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2022-21706HigFeb 26, 2022
    risk 0.00cvss 7.2epss 0.01

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…

  • CVE-2019-25058HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

  • CVE-2022-0727MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-0451MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to…

  • CVE-2022-25318MedFeb 18, 2022
    risk 0.00cvss 4.3epss 0.01

    An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.

  • CVE-2022-23627MedFeb 8, 2022
    risk 0.00cvss 5.0epss 0.01

    ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)…

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2021-41571MedFeb 1, 2022
    risk 0.00cvss 6.5epss 0.02

    In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, and it is supposed…

  • CVE-2021-46561HigJan 26, 2022
    risk 0.00cvss 7.2epss 0.01

    controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context…

  • CVE-2022-21707MedJan 21, 2022
    risk 0.00cvss 6.3epss 0.01

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…

  • CVE-2022-21678MedJan 13, 2022
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``…

  • CVE-2021-45457HigJan 6, 2022
    risk 0.00cvss 7.5epss 0.02

    In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.

  • CVE-2021-28661MedOct 7, 2021
    risk 0.00cvss 4.3epss 0.01

    Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.

  • CVE-2021-41093HigOct 4, 2021
    risk 0.00cvss 7.4epss 0.01

    Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an…

  • CVE-2021-41082HigSep 20, 2021
    risk 0.00cvss 7.5epss 0.02

    Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not…

  • CVE-2021-38698MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.02

    HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.