CWE-863
Incorrect Authorization
Description
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Hierarchy (View 1000)
CVEs mapped to this weakness (4,238)
page 211 of 212| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-24841 | Med | 0.00 | 6.5 | 0.01 | Apr 18, 2022 | fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In… | ||
| CVE-2022-1224 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2022-1223 | Med | 0.00 | 6.5 | 0.01 | Apr 4, 2022 | Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6. | ||
| CVE-2022-0406 | Med | 0.00 | 4.3 | 0.01 | Apr 3, 2022 | Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16. | ||
| CVE-2022-1177 | Med | 0.00 | 4.3 | 0.01 | Mar 30, 2022 | Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0. | ||
| CVE-2022-24755 | Hig | 0.00 | 8.1 | 0.02 | Mar 15, 2022 | Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired… | ||
| CVE-2022-24128 | Hig | 0.00 | 8.0 | 0.01 | Mar 13, 2022 | Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer… | ||
| CVE-2022-24714 | Med | 0.00 | 5.3 | 0.01 | Mar 8, 2022 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with… | ||
| CVE-2022-0829 | Hig | 0.00 | 8.1 | 0.01 | Mar 2, 2022 | Improper Authorization in GitHub repository webmin/webmin prior to 1.990. | ||
| CVE-2022-21706 | Hig | 0.00 | 7.2 | 0.01 | Feb 26, 2022 | Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack… | ||
| CVE-2022-0727 | Med | 0.00 | 5.4 | 0.01 | Feb 23, 2022 | Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0. | ||
| CVE-2022-0451 | Med | 0.00 | 6.5 | 0.01 | Feb 18, 2022 | Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to… | ||
| CVE-2022-25318 | Med | 0.00 | 4.3 | 0.01 | Feb 18, 2022 | An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups. | ||
| CVE-2022-23627 | Med | 0.00 | 5.0 | 0.01 | Feb 8, 2022 | ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)… | ||
| CVE-2022-21713 | Med | 0.00 | 4.3 | 0.01 | Feb 8, 2022 | Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the… | ||
| CVE-2021-46561 | Hig | 0.00 | 7.2 | 0.01 | Jan 26, 2022 | controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context… | ||
| CVE-2022-21707 | Med | 0.00 | 6.3 | 0.01 | Jan 21, 2022 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for… | ||
| CVE-2022-21678 | Med | 0.00 | 4.3 | 0.01 | Jan 13, 2022 | Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``… | ||
| CVE-2015-5251 | 0.00 | — | 0.02 | Oct 26, 2015 | OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*. | |||
| CVE-2015-4106 | 0.00 | — | 0.00 | Jun 3, 2015 | QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact… |
- risk 0.00cvss 6.5epss 0.01
fleetdm/fleet is an open source device management, built on osquery. All versions of fleet making use of the teams feature are affected by this authorization bypass issue. Fleet instances without teams, or with teams but without restricted team accounts are not affected. In…
- risk 0.00cvss 6.5epss 0.01
Improper Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- risk 0.00cvss 6.5epss 0.01
Incorrect Authorization in GitHub repository phpipam/phpipam prior to 1.4.6.
- risk 0.00cvss 4.3epss 0.01
Improper Authorization in GitHub repository janeczku/calibre-web prior to 0.6.16.
- risk 0.00cvss 4.3epss 0.01
Accounting User Can Download Patient Reports in openemr in GitHub repository openemr/openemr prior to 6.1.0.
- risk 0.00cvss 8.1epss 0.02
Bareos is open source software for backup, archiving, and recovery of data for operating systems. When Bareos Director >= 18.2 >= 18.2 but prior to 21.1.0, 20.0.6, and 19.2.12 is built and configured for PAM authentication, it will skip authorization checks completely. Expired…
- risk 0.00cvss 8.0epss 0.01
Timescale TimescaleDB 1.x and 2.x before 2.5.2 may allow privilege escalation during extension installation. The installation process uses commands such as CREATE x IF NOT EXIST that allow an unprivileged user to precreate objects. These objects will be used by the installer…
- risk 0.00cvss 5.3epss 0.01
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with…
- risk 0.00cvss 8.1epss 0.01
Improper Authorization in GitHub repository webmin/webmin prior to 1.990.
- risk 0.00cvss 7.2epss 0.01
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organizations is vulnerable to an attack…
- risk 0.00cvss 5.4epss 0.01
Improper Access Control in GitHub repository chocobozzz/peertube prior to 4.1.0.
- risk 0.00cvss 6.5epss 0.01
Dart SDK contains the HTTPClient in dart:io library whcih includes authorization headers when handling cross origin redirects. These headers may be explicitly set and contain sensitive information. By default, HttpClient handles redirection logic. If a request is sent to…
- risk 0.00cvss 4.3epss 0.01
An issue was discovered in Cerebrate through 1.4. An incorrect sharing group ACL allowed an unprivileged user to edit and modify sharing groups.
- risk 0.00cvss 5.0epss 0.01
ArchiSteamFarm (ASF) is a C# application with primary purpose of idling Steam cards from multiple accounts simultaneously. Due to a bug in ASF code, introduced in version V5.2.2.2, the program didn't adequately verify effective access of the user sending proxy (i.e. `[Bots]`)…
- risk 0.00cvss 4.3epss 0.01
Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…
- risk 0.00cvss 7.2epss 0.01
controller/org.controller/org.controller.js in the CVE Services API 1.1.1 before 5c50baf3bda28133a3bc90b854765a64fb538304 allows an organizational administrator to transfer a user account to an arbitrary new organization, and thereby achieve unintended access within the context…
- risk 0.00cvss 6.3epss 0.01
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for…
- risk 0.00cvss 4.3epss 0.01
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles private were still visible in the ``…
- CVE-2015-5251Oct 26, 2015risk 0.00cvss —epss 0.02
OpenStack Image Service (Glance) before 2014.2.4 (juno) and 2015.1.x before 2015.1.2 (kilo) allow remote authenticated users to change the status of their images and bypass access restrictions via the HTTP x-image-meta-status header to images/*.
- CVE-2015-4106Jun 3, 2015risk 0.00cvss —epss 0.00
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact…