VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (4,238)

page 211 of 212
  • CVE-2022-24841MedApr 18, 2022
    risk 0.00cvss 6.5epss 0.01

    fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…

  • CVE-2022-1224MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-1223MedApr 4, 2022
    risk 0.00cvss 6.5epss 0.01

    Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.

  • CVE-2022-0406MedApr 3, 2022
    risk 0.00cvss 4.3epss 0.01

    Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.

  • CVE-2022-1177MedMar 30, 2022
    risk 0.00cvss 4.3epss 0.01

    Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.

  • CVE-2022-24755HigMar 15, 2022
    risk 0.00cvss 8.1epss 0.02

    Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired…

  • CVE-2022-24128HigMar 13, 2022
    risk 0.00cvss 8.0epss 0.01

    Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…

  • CVE-2022-24714MedMar 8, 2022
    risk 0.00cvss 5.3epss 0.01

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with…

  • CVE-2022-0829HigMar 2, 2022
    risk 0.00cvss 8.1epss 0.01

    Improper Authorization in GitHub repository webmin/webmin prior to 1.990.

  • CVE-2022-21706HigFeb 26, 2022
    risk 0.00cvss 7.2epss 0.01

    Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…

  • CVE-2022-0727MedFeb 23, 2022
    risk 0.00cvss 5.4epss 0.01

    Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.

  • CVE-2022-0451MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.01

    Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to…

  • CVE-2022-25318MedFeb 18, 2022
    risk 0.00cvss 4.3epss 0.01

    An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.

  • CVE-2022-23627MedFeb 8, 2022
    risk 0.00cvss 5.0epss 0.01

    ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)…

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2021-46561HigJan 26, 2022
    risk 0.00cvss 7.2epss 0.01

    controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context…

  • CVE-2022-21707MedJan 21, 2022
    risk 0.00cvss 6.3epss 0.01

    wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…

  • CVE-2022-21678MedJan 13, 2022
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``…

  • CVE-2015-5251Oct 26, 2015
    risk 0.00cvss —epss 0.02

    OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.

  • CVE-2015-4106Jun 3, 2015
    risk 0.00cvss —epss 0.00

    QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact…