CWE-284
5,470 CVEs • Abstraction: Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVEs (5,470)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts |
Unauthenticated ReDoS via CODEOWNERS pattern matching allows denial of service |
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Improper access control in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. |
Gitea versions up to and including 1.26.1 allow OAuth2 access token scope enforcement to be bypassed through HTTP Basic authentication. |
Gitea versions before 1.25.5 accept malformed or injected forwarded-proto values when detecting public URLs, allowing spoofed canonical URL generation. |
Gitea versions before 1.25.5 allow draft release data or attachments to be accessed without the required write permission. |
Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests. |
Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the expected verifier check. |
Gitea versions before 1.25.5 have insufficient visibility checks in organization permission APIs for hidden members and private organizations. |
Gitea versions before 1.25.5 have insufficient permission checks for updating or rebasing pull request branches. |
Gitea 1.26.2 allows fork synchronization to continue after a parent repository changes from public to private, exposing data to a fork that should no longer be authorized. |
Gitea versions before 1.26.0 allow API users to fork a repository into an organization without first passing the CanCreateOrgRepo check, which can expose organization secrets. |
Gitea versions before 1.25.5 have insufficient permission checks when listing tracked time entries. |
Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are ena...Show more |
Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. |
A flaw was found in the ClientResource component of Keycloak's admin services when Fine-Grained Admin Permissions (FGAP) v2 is enabled. This issue allows a delegated administrator, who should only have limited control ov...Show more |
A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2...Show more |
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain...Show more |
Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. |