VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,183)

page 206 of 210
  • CVE-2022-1706MedMay 17, 2022
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…

  • CVE-2022-24865MedApr 20, 2022
    risk 0.00cvss 6.5epss 0.01

    HumHub is an Open Source Enterprise Social Network. In affected versions users who are forced to change their password by an administrator may retrieve other users' data. This issue has been resolved by commit `eb83de20`. It is recommended that the HumHub is upgraded to 1.11.0,…

  • CVE-2022-24841MedApr 18, 2022
    risk 0.00cvss 6.5epss 0.01

    fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…

  • CVE-2022-1224MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-1223MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-0406MedApr 3, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

  • CVE-2022-24755HigMar 15, 2022
    risk 0.00cvss 8.1epss 0.02

    Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired…

  • CVE-2022-24128HigMar 13, 2022
    risk 0.00cvss 8.0epss 0.01

    Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…

  • CVE-2021-41233MedMar 10, 2022
    risk 0.00cvss 6.5epss 0.01

    Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful…

  • CVE-2022-24714MedMar 8, 2022
    risk 0.00cvss 5.3epss 0.01

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with…

  • CVE-2021-41241MedMar 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted…

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2022-21706HigFeb 26, 2022
    risk 0.00cvss 7.2epss 0.01

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…

  • CVE-2019-25058HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

  • CVE-2022-0727MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-0451MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to…

  • CVE-2022-25318MedFeb 18, 2022
    risk 0.00cvss 4.3epss 0.01

    An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.

  • CVE-2022-23627MedFeb 8, 2022
    risk 0.00cvss 5.0epss 0.01

    ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)…

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…