VYPR

CWE-863

Incorrect Authorization

ClassIncompleteLikelihood: High

Description

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Hierarchy (View 1000)

CVEs mapped to this weakness (3,736)

page 86 of 187
  • CVE-2022-29271MedJun 29, 2022
    risk 0.42cvss 6.5epss 0.02

    In Nagios XI through 5.8.5, a read-only Nagios user (due to an incorrect permission check) is able to schedule downtime for any host/services. This allows an attacker to permanently disable all monitoring checks.

  • CVE-2022-34180HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in the HTTP endpoint it provides for "unprotected" status badge access, allowing attackers without any permissions to obtain the build status badge icon for any…

  • CVE-2022-34175HigJun 23, 2022
    risk 0.42cvss 7.5epss 0.01

    Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby directly accessing some view fragments containing sensitive information, bypassing any permission checks in the corresponding view.

  • CVE-2022-31589MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

  • CVE-2021-40616MedJun 14, 2022
    risk 0.42cvss 6.5epss 0.01

    thinkcmf v5.1.7 has an unauthorized vulnerability. The attacker can modify the password of the administrator account with id 1 through the background user management group permissions. The use condition is that the background user management group authority is required.

  • CVE-2022-31043HigJun 10, 2022
    risk 0.42cvss 7.5epss 0.02

    Guzzle is an open source PHP HTTP client. In affected versions `Authorization` headers on requests are sensitive information. On making a request using the `https` scheme to a server which responds with a redirect to a URI with the `http` scheme, we should not forward the…

  • CVE-2022-1936MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Deploy Token to misuse it from any…

  • CVE-2022-1935MedJun 6, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Project Trigger Token to misuse it from any…

  • CVE-2022-29773MedJun 3, 2022
    risk 0.42cvss 6.5epss 0.01

    An access control issue in aleksis/core/util/auth_helpers.py: ClientProtectedResourceMixin of AlekSIS-Core v2.8.1 and below allows attackers to access arbitrary scopes if no allowed scopes are specifically set.

  • CVE-2022-24584MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.01

    Incorrect access control in Yubico OTP functionality of the YubiKey hardware tokens along with the Yubico OTP validation server. The Yubico OTP supposedly creates hardware bound second factor credentials. When a user reprograms the OTP functionality by "writing" it on a token…

  • CVE-2022-28601MedMay 10, 2022
    risk 0.42cvss 6.5epss 0.02

    A Two-Factor Authentication (2FA) bypass vulnerability in "Simple 2FA Plugin for Moodle" by LMS Doctor allows remote attackers to overwrite the phone number used for confirmation via the profile.php file. Therefore, allowing them to bypass the phone verification mechanism.

  • CVE-2022-1466MedApr 26, 2022
    risk 0.42cvss 6.5epss 0.01

    Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.

  • CVE-2021-37517HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

  • CVE-2022-24778HigMar 25, 2022
    risk 0.42cvss 7.5epss 0.03

    The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt function `CheckAuthorization` is supposed to check whether…

  • CVE-2022-0633MedFeb 17, 2022
    risk 0.42cvss 6.5epss 0.02

    The UpdraftPlus WordPress plugin Free before 1.22.3 and Premium before 2.22.3 do not properly validate a user has the required privileges to access a backup's nonce identifier, which may allow any users with an account on the site (such as subscriber) to download the most recent…

  • CVE-2022-25270MedFeb 17, 2022
    risk 0.42cvss 6.5epss 0.01

    The Quick Edit module does not properly check entity access in some circumstances. This could result in users with the "access in-place editing" permission viewing some content they are are not authorized to access. Sites are only affected if the QuickEdit module (which comes…

  • CVE-2022-0309MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.99 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2022-0117MedFeb 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2020-13677HigFeb 11, 2022
    risk 0.42cvss 7.5epss 0.01

    Under some circumstances, the Drupal core JSON:API module does not properly restrict access to certain content, which may result in unintended access bypass. Sites that do not have the JSON:API module enabled are not affected.

  • CVE-2021-24947MedFeb 7, 2022
    risk 0.42cvss 6.5epss 0.03

    The RVM WordPress plugin before 6.4.2 does not have proper authorisation, CSRF checks and validation of the rvm_upload_regions_file_path parameter in the rvm_import_regions AJAX action, allowing any authenticated user, such as subscriber, to read arbitrary files on the web server