CWE-281— Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.— MITRE CWE catalog
358 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-281page 3 of 8
- CVE-2021-1004HIGHCVSS 7.8EG 7.82021-12-15
In getConfiguredNetworks of WifiServiceImpl.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local escalation of privilege with no addi…
- CVE-2021-1010MEDIUMCVSS 5.5EG 5.52021-12-15
In getSigningKeySet of PackageManagerService.java, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product…
- CVE-2021-1025MEDIUMCVSS 5.5EG 5.52021-12-15
In hasNamedWallpaper of WallpaperManagerService.java, there is a possible way to determine whether an app is installed, without query permissions, due to a missing permission check. This could lead to local information disclosure with no a…
- CVE-2021-20263LOWCVSS 3.3EG 3.32021-03-09
A flaw was found in the virtio-fs shared file system daemon (virtiofsd) of QEMU. The new 'xattrmap' option may cause the 'security.capability' xattr in the guest to not drop on file write, potentially leading to a modified, privileged exec…
- CVE-2021-21379HIGHCVSS 7.7EG 7.72021-03-12
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions of XWiki Platform, the `{{wikimacrocontent}}` executes the content with the rights of the wiki macro author inste…
- CVE-2021-21735MEDIUMCVSS 6.5EG 6.52021-06-10
A ZTE product has an information leak vulnerability. Due to improper permission settings, an attacker with ordinary user permissions could exploit this vulnerability to obtain some sensitive user information through the wizard page without…
- CVE-2021-22137MEDIUMCVSS 5.3EG 5.32021-05-13
In Elasticsearch versions before 7.11.2 and 6.8.15 a document disclosure flaw was found when Document or Field Level Security is used. Search queries do not properly preserve security permissions when executing certain cross-cluster search…
- CVE-2021-22382MEDIUMCVSS 6.5EG 6.52021-06-22
Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerab…
- CVE-2021-23963MEDIUMCVSS 4.3EG 4.32021-02-26
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.
- CVE-2021-29971CRITICALCVSS 9.8EG 9.82021-08-05
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. *This bug only affects Firefox for Android. Other operating sys…
- CVE-2021-30279HIGHCVSS 7.8EG 7.82022-01-03
Possible access control violation while setting current permission for VMIDs due to improper permission masking in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdrag…
- CVE-2021-30482HIGHCVSS 7.5EG 7.52021-05-11
In JetBrains UpSource before 2020.1.1883, application passwords were not revoked correctly
- CVE-2021-30827HIGHCVSS 7.8EG 7.82021-10-19
A permissions issue existed. This issue was addressed with improved permission validation. This issue is fixed in Security Update 2021-005 Catalina, macOS Big Sur 11.6. A local attacker may be able to elevate their privileges.
- CVE-2021-30912MEDIUMCVSS 5.5EG 5.52021-08-24
The issue was addressed with improved permissions logic. This issue is fixed in macOS Monterey 12.0.1, Security Update 2021-007 Catalina, macOS Big Sur 11.6.1. A malicious application may gain access to a user's Keychain items.
- CVE-2021-32465HIGHCVSS 8.8EG 8.82021-08-04
An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an att…
- CVE-2021-33990CRITICALCVSS 9.8EG 9.82023-04-16
Liferay Portal 6.2.5 allows Command=FileUpload&Type=File&CurrentFolder=/ requests when frmfolders.html exists. NOTE: The vendor disputes this issue because the exploit reference link only shows frmfolders.html is accessible and does not de…
- CVE-2021-3414HIGHCVSS 8.1EG 8.12022-08-26
A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and manage other organizations are also granted. The highest threat from this vulnerability is to data co…
- CVE-2021-3418MEDIUMCVSS 6.4EG 6.42021-03-15
If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validation. The booted kernel will think it was booted in secureboot mode and will implement lockdown, yet …
- CVE-2021-3495HIGHCVSS 8.8EG 8.82021-06-01
An incorrect access control flaw was found in the kiali-operator in versions before 1.33.0 and before 1.24.7. This flaw allows an attacker with a basic level of access to the cluster (to deploy a kiali operand) to use this vulnerability an…
- CVE-2021-35079MEDIUMCVSS 6.2EG 6.22022-06-14
Improper validation of permissions for third party application accessing Telephony service API can lead to information disclosure in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdrago…
- CVE-2021-3523HIGHCVSS 7.5EG 7.52022-04-27
A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an attacker to bypass security restrictions for an API request when hosting multiple APIs on the same I…
- CVE-2021-37006HIGHCVSS 7.5EG 7.52021-11-23
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability will cause the confidentiality of users is affected.
- CVE-2021-37044HIGHCVSS 7.5EG 7.52021-12-08
There is a Permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may affect service availability.
- CVE-2021-37056MEDIUMCVSS 5.3EG 5.32021-12-07
There is an Improper permission control vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information.
- CVE-2021-37086HIGHCVSS 8.6EG 8.62021-12-07
There is a Improper Preservation of Permissions vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to attackers which can isolate and read synchronization files of other applications across the UID sa…
- CVE-2021-3847HIGHCVSS 7.8EG 7.82022-04-01
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this …
- CVE-2021-38553MEDIUMCVSS 4.4EG 4.42021-08-13
HashiCorp Vault and Vault Enterprise 1.4.0 through 1.7.3 initialized an underlying database file associated with the Integrated Storage feature with excessively broad filesystem permissions. Fixed in Vault and Vault Enterprise 1.8.0.
- CVE-2021-39622HIGHCVSS 7.8EG 7.82022-01-14
In GBoard, there is a possible way to bypass Factory Reset Protection due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex…
- CVE-2021-39695HIGHCVSS 7.8EG 7.82022-03-16
In createOrUpdate of BasePermission.java, there is a possible permission bypass due to a logic error in the code. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for ex…
- CVE-2021-39697HIGHCVSS 7.8EG 7.82022-03-16
In checkFileUriDestination of DownloadProvider.java, there is a possible way to bypass external storage private directories protection due to a missing permission check. This could lead to local escalation of privilege with User execution …
- CVE-2021-39704HIGHCVSS 7.8EG 7.82022-03-16
In deleteNotificationChannelGroup of NotificationManagerService.java, there is a possible way to run foreground service without user notification due to a permissions bypass. This could lead to local escalation of privilege with no additio…
- CVE-2021-39897LOWCVSS 2.6EG 2.62021-11-05
Improper access control in GitLab CE/EE version 10.5 and above allowed subgroup members with inherited access to a project from a parent group to still have access even after the subgroup is transferred
- CVE-2021-41089LOWCVSS 2.8EG 2.82021-10-04
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where attempting to copy files using `docker cp` into a specially-crafted container can result in Unix file permi…
- CVE-2021-41091MEDIUMCVSS 6.3EG 6.32021-10-04
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted pe…
- CVE-2021-43708MEDIUMCVSS 5.5EG 5.52022-04-21
The Labeling tool in Titus Classification Suite 18.8.1910.140 allows users to avoid the generation of a classification label by using Excel's safe mode.
- CVE-2021-43816HIGHCVSS 8.0EG 8.02022-01-05
containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), an unprivileged pod …
- CVE-2021-44512HIGHCVSS 7.0EG 7.02021-12-07
World-writable permissions on the /tmp/tmate/sessions directory in tmate-ssh-server 2.3.0 allow a local attacker to compromise the integrity of session handling, or obtain the read-write session ID from a read-only session symlink in this …
- CVE-2021-45008HIGHCVSS 8.8EG 8.82022-02-21
Plesk CMS 18.0.37 is affected by an insecure permissions vulnerability that allows privilege Escalation from user to admin rights. OTE: the vendor states that this is only a site-specific problem on websites of one or more Plesk users
- CVE-2021-45446HIGHCVSS 5.0EG 7.52022-11-02
A vulnerability in Hitachi Vantara Pentaho Business Analytics Server versions before 9.2.0.2 and 8.3.0.25 does not cascade the hidden property to the children of the Home folder. This directory listing provides an attacker with the co…
- CVE-2022-0330HIGHCVSS 7.8EG 7.82022-03-25
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the sys…
- CVE-2022-1227HIGHCVSS 8.8EG 8.82022-04-29
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'pod…
- CVE-2022-21203HIGHCVSS 7.8EG 7.82022-02-09
Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-22472HIGHCVSS 8.8EG 8.82022-06-30
IBM Spectrum Protect Plus Container Backup and Restore (10.1.5 through 10.1.10.2 for Kubernetes and 10.1.7 through 10.1.10.2 for Red Hat OpenShift) could allow a remote attacker to bypass IBM Spectrum Protect Plus role based access control…
- CVE-2022-22650MEDIUMCVSS 5.5EG 5.52022-03-18
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.6.5, macOS Monterey 12.3, Security Update 2022-003 Catalina. A plug-in may be able to inherit the application's permissions and access user data.
- CVE-2022-24428HIGHCVSS 6.3EG 8.82022-04-08
Dell PowerScale OneFS, versions 8.2.x, 9.0.0.x, 9.1.0.x, 9.2.0.x, 9.2.1.x, and 9.3.0.x, contain an improper preservation of privileges. A remote filesystem user with a local account could potentially exploit this vulnerability, leading to …
- CVE-2022-24618HIGHCVSS 7.8EG 7.82022-03-10
Heimdal.Wizard.exe installer in Heimdal Premium Security 2.5.395 and earlier has insecure permissions, which allows unprivileged local users to elevate privileges to SYSTEM via the "Browse For Folder" window accessible by triggering a "Rep…
- CVE-2022-26024HIGHCVSS 6.7EG 7.82022-11-11
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-27215MEDIUMCVSS 4.3EG 4.32022-03-15
A missing permission check in Jenkins Release Helper Plugin 1.3.3 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.
- CVE-2022-2787MEDIUMCVSS 4.3EG 4.32022-08-27
Schroot before 1.6.13 had too permissive rules on chroot or session names, allowing a denial of service on the schroot service for all users that may start a schroot session.
- CVE-2022-29594HIGHCVSS 7.8EG 7.82022-06-02
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
Map vulnerabilities like CWE-281 to your infrastructure
EchelonGraph correlates every CVE — across CWE-281 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →