← Back
CWE-863

3,038 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,038)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Nov 21, 2024
Dec 23, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
1Nette
1Latte
Nov 21, 2024
Dec 17, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, addin...Show more
This affects the package latte/latte before 2.10.6. There is a way to bypass allowFunctions that will affect the security of the application. When the template is set to allow/disallow the use of certain functions, adding control characters (x00-x08) after the function will bypass these restrictions.Show less
1Wisc
1Htcondor
Nov 21, 2024
Dec 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in HTCondor 9.0.x before 9.0.4 and 9.1.x before 9.1.2. When authenticating to an HTCondor daemon using a SciToken, a user may be granted authorizations beyond what the token should allow.
1Google
1Android
Nov 21, 2024
Dec 15, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. Use...Show more
In stopVpnProfile of Vpn.java, there is a possible VPN profile reset due to a permissions bypass. This could lead to local escalation of privilege CONTROL_ALWAYS_ON_VPN with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-191382886Show less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 13, 2021
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a...Show more
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revokedShow less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possess...Show more
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
1Gitlab
1Gitlab
Nov 21, 2024
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to...Show more
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.Show less
1Get Custom Field Values Project
1Get Custom Field Values
Nov 21, 2024
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The Get Custom Field Values WordPress plugin before 4.0 allows users with a role as low as Contributor to access other posts metadata without validating the permissions. Eg. contributors can access admin posts metadata.
1Page/post Content Shortcode Project
1Page/post Content Shortcode
Nov 21, 2024
Dec 13, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages th...Show more
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.Show less
1Hashicorp
1Consul
Nov 21, 2024
Dec 12, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintende...Show more
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control. An ACL token (with the default operator:write permissions) in one namespace can be used for unintended privilege escalation in a different namespace.Show less
2Ibm
Netapp
2Db2
Oncommand Insight
Nov 21, 2024
Dec 9, 2021
N/A· v4
8.7 HIGH· v3
5.5 MEDIUM· v2
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files. IBM X-Force ID: 199914.
2Debian
Mozilla
4Debian Linux
FirefoxFirefox Esr+1 more
Nov 21, 2024
Dec 8, 2021
N/A· v4
10.0 CRITICAL· v3
7.5 HIGH· v2
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thu...Show more
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.Show less
1Fortinet
1Fortiweb
Nov 21, 2024
Dec 8, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the L...Show more
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.Show less
1Fortinet
1Fortiwlc
Nov 21, 2024
Dec 8, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypass...Show more
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.Show less
1Inveniosoftware
1Invenio Drafts Resources
Nov 21, 2024
Dec 6, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions whe...Show more
Invenio-Drafts-Resources is a submission/deposit module for Invenio, a software framework for research data management. Invenio-Drafts-Resources prior to versions 0.13.7 and 0.14.6 does not properly check permissions when a record is published. The vulnerability is exploitable in a default installation of InvenioRDM. An authenticated a user is able via REST API calls to publish draft records of other users if they know the record identifier and the draft validates (e.g. all require fields filled out). An attacker is not able to modify the data in the record, and thus e.g. *cannot* change a record from restricted to public. The problem is patched in Invenio-Drafts-Resources v0.13.7 and 0.14.6, which is part of InvenioRDM v6.0.1 and InvenioRDM v7.0 respectively.Show less
1Wpserveur
1Wps Hide Login
Nov 21, 2024
Dec 6, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
1Bookstackapp
1Bookstack
Nov 21, 2024
Nov 30, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
bookstack is vulnerable to Improper Access Control
1Bulk Datetime Change Project
1Bulk Datetime Change
Nov 21, 2024
Nov 29, 2021
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other user...Show more
The Bulk Datetime Change WordPress plugin before 1.12 does not enforce capability checks which allows users with Contributor roles to 1) list private post titles of other users and 2) change the posted date of other users' posts.Show less
2Fedoraproject
Moodle
3Extra Packages For Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 22, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.