← Back
CWE-284

5,090 CVEs • Abstraction: Pillar

Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

JSON object

Loading...

CVEs (5,090)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
1Thunderbolt Dch Driver
Nov 21, 2024
Feb 14, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
Improper access control in the Intel(R) Thunderbolt(TM) DCH drivers for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
1Dell
2Supportassist For Business Pcs
Supportassist For Home Pcs
Nov 21, 2024
Feb 14, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respecti...Show more
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code, in the Windows system context, and confined to that specific local PC. Show less
1Typo3
1Typo3
Nov 21, 2024
Feb 13, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This a...Show more
TYPO3 is an open source PHP based web content management system released under the GNU GPL. In affected versions of TYPO3 entities of the File Abstraction Layer (FAL) could be persisted directly via `DataHandler`. This allowed attackers to reference files in the fallback storage directly and retrieve their file names and contents. The fallback storage ("zero-storage") is used as a backward compatibility layer for files located outside properly configured file storages and within the public web root directory. Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 version 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, or 13.0.1 which fix the problem described. When persisting entities of the File Abstraction Layer directly via DataHandler, `sys_file` entities are now denied by default, and `sys_file_reference` & `sys_file_metadata` entities are not permitted to reference files in the fallback storage anymore. When importing data from secure origins, this must be explicitly enabled in the corresponding DataHandler instance by using `$dataHandler->isImporting = true;`. Show less
1Typo3
1Typo3
Nov 21, 2024
Feb 13, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed...Show more
TYPO3 is an open source PHP based web content management system released under the GNU GPL. The TYPO3-specific `t3://` URI scheme could be used to access resources outside of the users' permission scope. This encompassed files, folders, pages, and records (although only if a valid link-handling configuration was provided). Exploiting this vulnerability requires a valid backend user account. Users are advised to update to TYPO3 versions 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, 13.0.1 that fix the problem described. There are no known workarounds for this issue.Show less
1Amd
62Epyc 7203 Firmware
Epyc 7203p FirmwareEpyc 72f3 Firmware+59 more
Mar 20, 2025
Feb 13, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
-
-
May 7, 2025
Feb 13, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
1Amd
129Ryzen 3 3200u Firmware
Ryzen 3 3250c FirmwareRyzen 3 3250u Firmware+126 more
Mar 14, 2025
Feb 13, 2024
N/A· v4
6.0 MEDIUM· v3
N/A· v2
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability....Show more
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability. Show less
1Derhansen
1Event Management And Registration
Nov 21, 2024
Feb 13, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the u...Show more
sf_event_mgt is an event management and registration extension for the TYPO3 CMS based on ExtBase and Fluid. In affected versions the existing access control check for events in the backend module got broken during the update of the extension to TYPO3 12.4, because the `RedirectResponse` from the `$this->redirect()` function was never handled. This issue has been addressed in version 7.4.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Microsoft
1Entra Jira Sso Plugin
Nov 21, 2024
Feb 13, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Microsoft Entra Jira Single-Sign-On Plugin Elevation of Privilege Vulnerability
1Microsoft
1Azure Kubernetes Service
Nov 21, 2024
Feb 13, 2024
N/A· v4
9.0 CRITICAL· v3
N/A· v2
Microsoft Azure Kubernetes Service Confidential Container Remote Code Execution Vulnerability
1Microsoft
1Azure Site Recovery
Nov 21, 2024
Feb 13, 2024
N/A· v4
9.3 CRITICAL· v3
N/A· v2
Microsoft Azure Site Recovery Elevation of Privilege Vulnerability
1Microsoft
1Skype For Business Server
Nov 21, 2024
Feb 13, 2024
N/A· v4
5.7 MEDIUM· v3
N/A· v2
Skype for Business Information Disclosure Vulnerability
1Moodle
1Moodle
Nov 21, 2024
Feb 12, 2024
N/A· v4
3.3 LOW· v3
N/A· v2
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to...Show more
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.Show less
1Mattermost
1Mattermost Server
Nov 21, 2024
Feb 9, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Mattermost fails to check the required permissions in the POST /api/v4/channels/stats/member_count API resulting in channel member counts being leaked to a user without permissions.
1Minbrowser
1Min
Jun 16, 2025
Feb 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an X...Show more
In Min before 1.31.0, local files are not correctly treated as unique security origins, which allows them to improperly request cross-origin resources. For example, a local file may request other local files through an XML document.Show less
1Openobserve
1Openobserve
Nov 21, 2024
Feb 8, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" en...Show more
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A critical vulnerability has been identified in the "/api/{org_id}/users/{email_id}" endpoint. This vulnerability allows any authenticated user within an organization to remove any other user from that same organization, irrespective of their respective roles. This includes the ability to remove users with "Admin" and "Root" roles. By enabling any organizational member to unilaterally alter the user base, it opens the door to unauthorized access and can cause considerable disruptions in operations. The core of the vulnerability lies in the `remove_user_from_org` function in the user management system. This function is designed to allow organizational users to remove members from their organization. The function does not check if the user initiating the request has the appropriate administrative privileges to remove a user. Any user who is part of the organization, irrespective of their role, can remove any other user, including those with higher privileges. This vulnerability is categorized as an Authorization issue leading to Unauthorized User Removal. The impact is severe, as it compromises the integrity of user management within organizations. By exploiting this vulnerability, any user within an organization, without the need for administrative privileges, can remove critical users, including "Admins" and "Root" users. This could result in unauthorized system access, administrative lockout, or operational disruptions. Given that user accounts are typically created by "Admins" or "Root" users, this vulnerability can be exploited by any user who has been granted access to an organization, thereby posing a critical risk to the security and operational stability of the application. This issue has been addressed in release version 0.8.0. Users are advised to upgrade.Show less
1Openobserve
1Openobserve
Aug 27, 2025
Feb 8, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnera...Show more
OpenObserve is a observability platform built specifically for logs, metrics, traces, analytics, designed to work at petabyte scale. A vulnerability has been identified in the "/api/{org_id}/users" endpoint. This vulnerability allows any authenticated regular user ('member') to add new users with elevated privileges, including the 'root' role, to an organization. This issue circumvents the intended security controls for role assignments. The vulnerability resides in the user creation process, where the payload does not validate the user roles. A regular user can manipulate the payload to assign root-level privileges. This vulnerability leads to Unauthorized Privilege Escalation and significantly compromises the application's role-based access control system. It allows unauthorized control over application resources and poses a risk to data security. All users, particularly those in administrative roles, are impacted. This issue has been addressed in release version 0.8.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.Show less
1Remyandrade
1Daily Habit Tracker
Nov 21, 2024
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
1Pluginsandsnippets
1Simple Page Access Restriction
Apr 8, 2026
Feb 8, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers...Show more
The Simple Page Access Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.21 via the REST API. This makes it possible for unauthenticated attackers to bypass the plugin's page restriction and view page content.Show less
1Graylog
1Graylog
Nov 21, 2024
Feb 7, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_...Show more
Graylog is a free and open log management platform. Starting in version 2.0.0 and prior to versions 5.1.11 and 5.2.4, arbitrary classes can be loaded and instantiated using a HTTP PUT request to the `/api/system/cluster_config/` endpoint. Graylog's cluster config system uses fully qualified class names as config keys. To validate the existence of the requested class before using them, Graylog loads the class using the class loader. If a user with the appropriate permissions performs the request, arbitrary classes with 1-arg String constructors can be instantiated. This will execute arbitrary code that is run during class instantiation. In the specific use case of `java.io.File`, the behavior of the internal web-server stack will lead to information exposure by including the entire file content in the response to the REST request. Versions 5.1.11 and 5.2.4 contain a fix for this issue.Show less