CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (3,734)
page 184 of 187| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-41233 | Med | 0.00 | 6.5 | 0.01 | Mar 10, 2022 | Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful… | ||
| CVE-2022-24714 | Med | 0.00 | 5.3 | 0.01 | Mar 8, 2022 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with… | ||
| CVE-2021-41241 | Med | 0.00 | 4.3 | 0.01 | Mar 8, 2022 | Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted… | ||
| CVE-2022-0829 | Hig | 0.00 | 8.1 | 0.01 | Mar 2, 2022 | Improper Authorization in GitHub repository webmin/webmin prior to 1.990. | ||
| CVE-2022-21706 | Hig | 0.00 | 7.2 | 0.01 | Feb 26, 2022 | Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack… | ||
| CVE-2019-25058 | Hig | 0.00 | 7.8 | 0.00 | Feb 24, 2022 | An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future. | ||
| CVE-2022-0727 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-0451 | Med | 0.00 | 6.5 | 0.01 | Feb 18, 2022 | Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to… | ||
| CVE-2022-25318 | Med | 0.00 | 4.3 | 0.01 | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups. | ||
| CVE-2022-23627 | Med | 0.00 | 5.0 | 0.01 | Feb 8, 2022 | ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)… | ||
| CVE-2022-21713 | Med | 0.00 | 4.3 | 0.01 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the… | ||
| CVE-2021-41571 | Med | 0.00 | 6.5 | 0.02 | Feb 1, 2022 | In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, and it is supposed… | ||
| CVE-2021-46561 | Hig | 0.00 | 7.2 | 0.01 | Jan 26, 2022 | controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context… | ||
| CVE-2022-21707 | Med | 0.00 | 6.3 | 0.01 | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for… | ||
| CVE-2022-21678 | Med | 0.00 | 4.3 | 0.01 | Jan 13, 2022 | Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``… | ||
| CVE-2021-45457 | Hig | 0.00 | 7.5 | 0.02 | Jan 6, 2022 | In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions. | ||
| CVE-2021-28661 | Med | 0.00 | 4.3 | 0.01 | Oct 7, 2021 | Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass. | ||
| CVE-2021-41093 | Hig | 0.00 | 7.4 | 0.01 | Oct 4, 2021 | Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an… | ||
| CVE-2021-41082 | Hig | 0.00 | 7.5 | 0.02 | Sep 20, 2021 | Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not… | ||
| CVE-2021-38698 | Med | 0.00 | 6.5 | 0.02 | Sep 7, 2021 | HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2. |
- risk 0.00cvss 6.5epss 0.01
Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful…
- risk 0.00cvss 5.3epss 0.01
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with…
- risk 0.00cvss 4.3epss 0.01
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…
- risk 0.00cvss 8.1epss 0.01
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
- risk 0.00cvss 7.2epss 0.01
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…
- risk 0.00cvss 7.8epss 0.00
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
- risk 0.00cvss 5.4epss 0.01
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 6.5epss 0.01
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to…
- risk 0.00cvss 4.3epss 0.01
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
- risk 0.00cvss 5.0epss 0.01
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)…
- risk 0.00cvss 4.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…
- risk 0.00cvss 6.5epss 0.02
In Apache Pulsar it is possible to access data from BookKeeper that does not belong to the topics accessible by the authenticated user. The Admin API get-message-by-id requires the user to input a topic and a ledger id. The ledger id is a pointer to the data, and it is supposed…
- risk 0.00cvss 7.2epss 0.01
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context…
- risk 0.00cvss 6.3epss 0.01
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…
- risk 0.00cvss 4.3epss 0.01
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``…
- risk 0.00cvss 7.5epss 0.02
In Apache Kylin, Cross-origin requests with credentials are allowed to be sent from any origin. This issue affects Apache Kylin 2 version 2.6.6 and prior versions; Apache Kylin 3 version 3.1.2 and prior versions; Apache Kylin 4 version 4.0.0 and prior versions.
- risk 0.00cvss 4.3epss 0.01
Default SilverStripe GraphQL Server (aka silverstripe/graphql) 3.x through 3.4.1 permission checker not inherited by query subclass.
- risk 0.00cvss 7.4epss 0.01
Wire is an open source secure messenger. In affected versions if the an attacker gets an old but valid access token they can take over an account by changing the email. This issue has been resolved in version 3.86 which uses a new endpoint which additionally requires an…
- risk 0.00cvss 7.5epss 0.02
Discourse is a platform for community discussion. In affected versions any private message that includes a group had its title and participating user exposed to users that do not have access to the private messages. However, access control for the private messages was not…
- risk 0.00cvss 6.5epss 0.02
HashiCorp Consul and Consul Enterprise 1.10.1 Txn.Apply endpoint allowed services to register proxies for other services, enabling access to service traffic. Fixed in 1.8.15, 1.9.9 and 1.10.2.