← Back
CWE-668

730 CVEs • Abstraction: Class

Exposure of Resource to Wrong Sphere

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

JSON object

Loading...

CVEs (730)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Chef Identity
Jun 17, 2026
Jul 26, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
1Vocera
2Report Server
Voice Server
Jun 17, 2026
Jul 25, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the...Show more
An issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is an Access Control Violation for Database Operations. The Vocera Report Console contains a websocket interface that allows for the unauthenticated execution of various tasks and database functions. This includes system tasks, and backing up, loading, and clearing of the database.Show less
1Apache
1Inlong
Jun 17, 2026
Jul 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the pro...Show more
Exposure of Resource to Wrong Sphere Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.4.0 through 1.7.0. The attacker could use general users to delete and update the process, which only the admin can operate occurrences.  Users are advised to upgrade to Apache InLong's 1.8.0 or cherry-pick https://github.com/apache/inlong/pull/8109  to solve it.Show less
1Eyoucms
1Eyoucms
Jun 17, 2026
Jul 20, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
eyoucms v1.6.3 was discovered to contain an information disclosure vulnerability via the component /custom_model_path/recruit.filelist.txt.
1Hashicorp
1Nomad
Jun 17, 2026
Jul 20, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
HashiCorp Nomad Enterprise 1.2.11 up to 1.5.6, and 1.4.10 ACL policies using a block without a label generates unexpected results. Fixed in 1.6.0, 1.5.7, and 1.4.11.
1Archerirm
1Archer
Jun 17, 2026
Jul 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Archer Platform before v.6.13 fixed in v.6.12.0.6 and v.6.13.0 allows an authenticated attacker to obtain sensitive information via API calls related to data feeds and data publication.
1Archerirm
1Archer
Jun 17, 2026
Jul 14, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue in Archer Platform before v.6.13 and fixed in 6.12.0.6 and 6.13.0 allows an authenticated attacker to obtain sensitive information via a crafted URL.
1Issabel
1Pbx
Jun 17, 2026
Jul 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in issabel-pbx v.4.0.0-6 allows a remote attacker to obtain sensitive information via the modules directory
1Zoom
1Rooms
Jun 17, 2026
Jul 11, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure temporary file in the installer for Zoom Rooms for Windows before version 5.15.0 may allow an authenticated user to enable an escalation of privilege via local access.
1Marukyu
1Marukyu Line
Jul 9, 2026
Jul 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue found in Marukyu Line v.13.4.1 allows a remote attacker to gain access to sensitive information via the channel access token in the miniapp function.
1Palantir
1Foundry Job Tracker
Jun 17, 2026
Jul 10, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. T...Show more
A security defect was discovered in Foundry job-tracker that enabled users to query metadata related to builds on resources they did not have access to. This defect was resolved with the release of job-tracker 4.645.0. The service was rolled out to all affected Foundry instances. No further intervention is required. Show less
1Sick
1Icr890 4 Firmware
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Exposure of Sensitive Information to an Unauthorized Actor in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the system.
1Sick
1Icr890 4 Firmware
Jun 17, 2026
Jul 10, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Unauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the device via HTTP requests.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 6, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Vulnerability of kernel raw address leakage in the hang detector module. Successful exploitation of this vulnerability may affect service confidentiality.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Jul 5, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Key management vulnerability on system. Successful exploitation of this vulnerability may affect service availability and integrity.
1Wavlink
1Wl Wn531ax2 Firmware
Jun 17, 2026
Jun 30, 2023
N/A· v4
8.1 HIGH· v3
N/A· v2
Exposure of resource to wrong sphere issue exists in WL-WN531AX2 firmware versions prior to 2023526, which may allow a network-adjacent attacker to use functions originally available after login without logging in.
1Apple
5Ipados
Iphone OsMacos+2 more
Jun 17, 2026
Jun 23, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information...Show more
The issue was addressed with improved checks. This issue is fixed in iOS 16.5 and iPadOS 16.5, watchOS 9.5, tvOS 16.5, macOS Ventura 13.4. A person with physical access to a device may be able to view contact information from the lock screen.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obf...Show more
XWiki Platform is a generic wiki platform. Starting in version 7.3-milestone-1 and prior to versions 14.4.8, 14.10.6, and 15.1, ny user can call a REST endpoint and obtain the obfuscated passwords, even when the mail obfuscation is activated. The issue has been patched in XWiki 14.4.8, 14.10.6, and 15.1. There is no known workaround.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Jun 23, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail dis...Show more
XWiki Platform is a generic wiki platform. Starting in version 3.5-milestone-1 and prior to versions 14.4.8, 14.10.4, and 15.0-rc-1, the mail obfuscation configuration was not fully taken into account. While the mail displayed to the end user was obfuscated, the rest response was also containing the mail unobfuscated and users were able to filter and sort on the unobfuscated, allowing them to infer the mail content. The consequence was the possibility to retrieve the email addresses of all users even when obfuscated. This has been patched in XWiki 14.4.8, 14.10.4, and 15.0-rc-1.Show less
1Proofpoint
1Threat Response Auto Pull
Jun 17, 2026
Jun 14, 2023
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated se...Show more
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could use these credentials to impersonate PTR/TRAP to these services. All versions prior to 5.10.0 are affected.  Show less