VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 84 of 187
  • CVE-2023-39154MedJul 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Incorrect permission checks in Jenkins Qualys Web App Scanning Connector Plugin 2.0.10 and earlier allow attackers with global Item/Configure permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing…

  • CVE-2023-38493HigJul 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might…

  • CVE-2023-34107MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch…

  • CVE-2023-34106MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information.…

  • CVE-2023-32219MedJun 12, 2023
    risk 0.42cvss 6.5epss 0.00

    A Mazda model (2015-2016) can be unlocked via an unspecified method.

  • CVE-2023-23604MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.

  • CVE-2023-31597MedMay 18, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue in Zammad v5.4.0 allows attackers to bypass e-mail verification using an arbitrary address and manipulate the data of the generated user. Attackers are also able to gain unauthorized access to existing tickets.

  • CVE-2023-28325MedMay 11, 2023
    risk 0.42cvss 6.5epss 0.00

    An improper authorization vulnerability exists in Rocket.Chat <6.0 that could allow a hacker to manipulate the rid parameter and change the updateMessage method that only checks whether the user is allowed to edit message in the target room.

  • CVE-2023-32060MedMay 9, 2023
    risk 0.42cvss 6.5epss 0.01

    DHIS2 Core contains the service layer and Web API for DHIS2, an information system for data capture. Starting in the 2.35 branch and prior to versions 2.36.13, 2.37.8, 2.38.2, and 2.39.0, when the Category Option Combination Sharing settings are configured to control access to…

  • CVE-2023-27954MedMay 8, 2023
    risk 0.42cvss 6.5epss 0.01

    The issue was addressed by removing origin information. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4, watchOS 9.4. A website may be able to track sensitive user information.

  • CVE-2023-31250MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    The file download facility doesn't sufficiently sanitize file paths in certain situations. This may result in users gaining access to private files that they should not have access to. Some sites may require configuration changes following this security release. Review the…

  • CVE-2023-1603MedApr 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.

  • CVE-2023-1202MedApr 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Permission bypass when importing or synchronizing entries in User vault in Devolutions Remote Desktop Manager 2023.1.9 and prior versions allows users with restricted rights to bypass entry permission via id collision.

  • CVE-2023-0952MedMar 1, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization.

  • CVE-2023-0814MedFeb 14, 2023
    risk 0.42cvss 6.5epss 0.01

    The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to sensitive information disclosure via the [user_meta] shortcode in versions up to, and including 3.9.0. This is due to insufficient restriction on sensitive user meta values that…

  • CVE-2023-21719MedJan 24, 2023
    risk 0.42cvss 6.5epss 0.02

    Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

  • CVE-2023-0133MedJan 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in in Permission prompts in Google Chrome on Android prior to 109.0.5414.74 allowed a remote attacker to bypass main origin permission delegation via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-46258MedJan 9, 2023
    risk 0.42cvss 6.5epss 0.01

    An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope. The Create or Update file contents API should enforce workflow scope. This…

  • CVE-2022-48216HigJan 4, 2023
    risk 0.42cvss 7.5epss 0.01

    Uniswap Universal Router before 1.1.0 mishandles reentrancy. This would have allowed theft of funds.

  • CVE-2022-23553HigDec 28, 2022
    risk 0.42cvss 7.5epss 0.01

    Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.