← Back
CWE-863

3,773 CVEs • Abstraction: Class • Likelihood of Exploit: High

Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

JSON object

Loading...

CVEs (3,773)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Vsphere
Nov 21, 2024
Apr 5, 2018
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java,...Show more
An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java, Reconfigure.java, Rename.java, RenameSnapshot.java, RevertToSnapshot.java, SuspendVm.java, TakeSnapshot.java, VSphereBuildStepContainer.java, vSphereCloudProvisionedSlave.java, vSphereCloudSlave.java, vSphereCloudSlaveTemplate.java, VSphereConnectionConfig.java, vSphereStep.java that allows attackers to perform form validation related actions, including sending numerous requests to the configured vSphere server, potentially resulting in denial of service, or send credentials stored in Jenkins with known ID to an attacker-specified server ("test connection").Show less
1Ibm
1Business Process Manager
Nov 21, 2024
Mar 30, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Due to incorrect authorization in IBM Business Process Manager 8.6 an attacker can claim and work on ad hoc tasks he is not assigned to. IBM X-Force ID: 136151.
1Gitlab
1Gitlab
Nov 21, 2024
Mar 22, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see eve...Show more
GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the Projects::MergeRequests::CreationsController component resulting in an attacker to see every project name and their respective namespace on a GitLab instance.Show less
1Gitlab
1Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the deployment keys component resulting in unauthorized use of deployment keys by guest users.
2Debian
Gitlab
2Debian Linux
Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.
1Gitlab
1Gitlab
Nov 21, 2024
Mar 21, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resulting in an information disclosure on any board object.
1Ncr
1S1 Dispenser Controller Firmware
Nov 21, 2024
Mar 20, 2018
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabiliti...Show more
Memory write mechanism in NCR S1 Dispenser controller before firmware version 0x0156 allows an unauthenticated user to upgrade or downgrade the firmware of the device, including to older versions with known vulnerabilities.Show less
3Canonical
DebianSamba
3Debian Linux
SambaUbuntu Linux
Nov 21, 2024
Mar 13, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including...Show more
On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' passwords, including administrative users and privileged service accounts (eg Domain Controllers).Show less
1Jenkins
1Promoted Builds
Nov 21, 2024
Mar 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Promoted Builds Plugin 2.31.1 and earlier in Status.java and ManualCondition.java that allow an attacker with read access to jobs to perform promotions.
1Jenkins
1Mercurial
Nov 21, 2024
Mar 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Mercurial Plugin version 2.2 and earlier in MercurialStatus.java that allows an attacker with network access to obtain a list of nodes and users.
1Jenkins
1Subversion
Nov 21, 2024
Mar 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a...Show more
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and users.Show less
1Jenkins
1Git
Nov 21, 2024
Mar 13, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Git Plugin version 3.7.0 and earlier in GitStatus.java that allows an attacker with network access to obtain a list of nodes and users.
1Jenkins
1Google Play Android Publisher
Nov 21, 2024
Mar 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.
1Jenkins
1Job And Node Ownership
Nov 21, 2024
Mar 13, 2018
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Jo...Show more
An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.Show less
1Jenkins
1Gerrit Trigger
Nov 21, 2024
Mar 13, 2018
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modi...Show more
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenkins.Show less
1Jenkins
1Gerrit Trigger
Nov 21, 2024
Mar 13, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retr...Show more
An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.Show less
1Freeipa
1Freeipa
Nov 21, 2024
Mar 13, 2018
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker c...Show more
Ipa versions 4.2.x, 4.3.x before 4.3.3 and 4.4.x before 4.4.3 did not properly check the user's permissions while modifying certificate profiles in IdM's certprofile-mod command. An authenticated, unprivileged attacker could use this flaw to modify profiles to issue certificates with arbitrary naming or key usage information and subsequently use such certificates for other attacks.Show less
1Huawei
1Ibmc Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is...Show more
Huawei iBMC V200R002C10; V200R002C20; V200R002C30 have an improper authorization vulnerability. The software incorrectly performs an authorization check when a normal user attempts to access certain information which is supposed to be accessed only by admin user. Successful exploit could cause information disclosure.Show less
1Atlassian
1Crucible
Nov 21, 2024
Feb 19, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an imprope...Show more
The SnippetRPCServiceImpl class in Atlassian Crucible before version 4.5.1 (the fixed version 4.5.x) and before 4.6.0 allows remote attackers to comment on snippets they do not have authorization to access via an improper authorization vulnerability.Show less
1Ivanti
1Endpoint Security
Jun 17, 2026
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting...Show more
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.Show less