CWE-668— Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.— MITRE CWE catalog
1,140 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-668page 10 of 23
- CVE-2021-39884MEDIUMCVSS 4.3EG 4.32021-10-05
In all versions of GitLab EE since version 8.13, an endpoint discloses names of private groups that have access to a project to low privileged users that are part of that project.
- CVE-2021-39892MEDIUMCVSS 4.3EG 4.32022-01-18
In all versions of GitLab CE/EE since version 12.0, a lower privileged user can import users from projects that they don't have a maintainer role on and disclose email addresses of those users.
- CVE-2021-39898MEDIUMCVSS 3.7EG 5.32021-11-05
In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.
- CVE-2021-39900LOWCVSS 2.0EG 2.72021-10-04
Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.
- CVE-2021-39915MEDIUMCVSS 5.3EG 5.32021-12-13
Improper access control in the GraphQL API in GitLab CE/EE affecting all versions starting from 13.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker to see the…
- CVE-2021-39969HIGHCVSS 7.5EG 7.52022-01-03
There is an Unauthorized file access vulnerability in Smartphones.Successful exploitation of this vulnerability may affect service confidentiality.
- CVE-2021-39971HIGHCVSS 7.5EG 7.52022-01-03
Password vault has a External Control of System or Configuration Setting vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
- CVE-2021-39972HIGHCVSS 7.5EG 7.52022-01-03
MyHuawei-App has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could compromise confidentiality.
- CVE-2021-39980MEDIUMCVSS 5.3EG 5.32022-01-03
Telephony application has a Exposure of Sensitive Information to an Unauthorized Actor vulnerability.Successful exploitation of this vulnerability could lead to sensitive information disclosure.
- CVE-2021-40005HIGHCVSS 7.5EG 7.52022-01-10
The distributed data service component has a vulnerability in data access control. Successful exploitation of this vulnerability may affect data confidentiality.
- CVE-2021-40012HIGHCVSS 7.5EG 7.52022-07-12
Vulnerability of pointers being incorrectly used during data transmission in the video framework. Successful exploitation of this vulnerability may affect confidentiality.
- CVE-2021-40051HIGHCVSS 7.5EG 7.52022-03-10
There is an unauthorized access vulnerability in system components. Successful exploitation of this vulnerability will affect confidentiality.
- CVE-2021-40086LOWCVSS 2.2EG 2.22021-08-25
An issue was discovered in PrimeKey EJBCA before 7.6.0. As part of the configuration of the aliases for SCEP, CMP, EST, and Auto-enrollment, the enrollment secret was reflected on a page (that can only be viewed by an administrator). While…
- CVE-2021-40288HIGHCVSS 7.5EG 7.52021-12-07
A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter spe…
- CVE-2021-40496MEDIUMCVSS 4.3EG 4.32021-10-12
SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attacker with logon functionality, to exploit the authentication function by using POST and form field to…
- CVE-2021-40497MEDIUMCVSS 5.3EG 5.32021-10-12
SAP BusinessObjects Analysis (edition for OLAP) - versions 420, 430, allows an attacker to exploit certain application endpoints to read sensitive data. These endpoints are normally exposed over the network and successful exploitation coul…
- CVE-2021-40639HIGHCVSS 7.5EG 7.52021-09-15
Improper access control in Jfinal CMS 5.1.0 allows attackers to access sensitive information via /classes/conf/db.properties&config=filemanager.config.js.
- CVE-2021-40862HIGHCVSS 8.8EG 8.82021-09-15
HashiCorp Terraform Enterprise up to v202108-1 contained an API endpoint that erroneously disclosed a sensitive URL to authenticated parties, which could be used for privilege escalation or unauthorized modification of a Terraform configur…
- CVE-2021-41011HIGHCVSS 7.5EG 7.52021-09-22
LINE client for iOS before 11.15.0 might expose authentication information for a certain service to external entities under certain conditions. This is usually impossible, but in combination with a server-side bug, attackers could get this…
- CVE-2021-41032MEDIUMCVSS 6.3EG 6.32022-05-04
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel sta…
- CVE-2021-41065HIGHCVSS 7.3EG 7.32021-12-14
An issue was discovered in Listary through 6. An attacker can create a \\.\pipe\Listary.listaryService named pipe and wait for a privileged user to open a session on the Listary installed host. Listary will automatically access the named p…
- CVE-2021-41088HIGHCVSS 8.0EG 8.02021-09-23
Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The ba…
- CVE-2021-41094MEDIUMCVSS 4.2EG 4.22021-10-04
Wire is an open source secure messenger. Users of Wire by Bund may bypass the mandatory encryption at rest feature by simply disabling their device passcode. Upon launching, the app will attempt to enable encryption at rest by generating e…
- CVE-2021-41140MEDIUMCVSS 5.3EG 5.32021-10-19
Discourse-reactions is a plugin for the Discourse platform that allows user to add their reactions to the post. In affected versions reactions given by user to secure topics and private messages are visible. This issue is patched in versio…
- CVE-2021-41329MEDIUMCVSS 6.5EG 6.52021-09-27
Datalust Seq before 2021.2.6259 allows users (with view filters applied to their accounts) to see query results not constrained by their view filter. This information exposure, caused by an internal cache key collision, occurs when the use…
- CVE-2021-41590MEDIUMCVSS 5.3EG 5.32021-10-27
In Gradle Enterprise through 2021.3, probing of the server-side network environment can occur via an SMTP configuration test. The installation configuration user interface available to administrators allows testing the configured SMTP serv…
- CVE-2021-41790HIGHCVSS 8.8EG 8.82021-10-21
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary …
- CVE-2021-4180MEDIUMCVSS 4.3EG 4.32022-03-23
An information exposure flaw in openstack-tripleo-heat-templates allows an external user to discover the internal IP or hostname. An attacker could exploit this by checking the www_authenticate_uri parameter (which is visible to all end us…
- CVE-2021-41847HIGHCVSS 8.8EG 8.82021-10-01
An issue was discovered in 3xLogic Infinias Access Control through 6.7.10708.0, affecting physical security. Users with login credentials assigned to a specific zone can send modified HTTP GET and POST requests, allowing them to view user …
- CVE-2021-41988HIGHCVSS 7.8EG 7.82023-01-26
Qlik NPrinting Designer through 21.14.3.0 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-41989HIGHCVSS 7.8EG 7.82023-01-26
Qlik QlikView through 12.60.20100.0 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-42001CRITICALCVSS 8.0EG 9.82022-04-30
PingID Desktop prior to 1.7.3 has a misconfiguration in the encryption libraries which can lead to sensitive data exposure. An attacker capable of exploiting this vulnerability may be able to successfully complete an MFA challenge via OTP.
- CVE-2021-42067MEDIUMCVSS 4.3EG 4.32022-01-14
In SAP NetWeaver AS for ABAP and ABAP Platform - versions 701, 702, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 786, an attacker authenticated as a regular user can use the S/4 Hana dashboard to reveal systems and services which…
- CVE-2021-42087MEDIUMCVSS 4.9EG 4.92021-10-07
An issue was discovered in Zammad before 4.1.1. An admin can discover the application secret via the API.
- CVE-2021-42116MEDIUMCVSS 4.3EG 4.32021-11-30
Incorrect Access Control in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 allows an authenticated remote attacker to view the Shape Editor and Settings, which are functionality for highe…
- CVE-2021-42254HIGHCVSS 7.8EG 7.82021-11-19
BeyondTrust Privilege Management prior to version 21.6 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-42255HIGHCVSS 7.8EG 7.82022-04-12
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
- CVE-2021-42301MEDIUMCVSS 3.3EG 4.62021-11-10
Azure RTOS Information Disclosure Vulnerability
- CVE-2021-42306HIGHCVSS 8.1EG 8.12021-11-24
An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not re…
- CVE-2021-42323LOWCVSS 3.3EG 3.32021-11-10
Azure RTOS Information Disclosure Vulnerability
- CVE-2021-42536HIGHCVSS 8.0EG 8.02021-10-22
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.
- CVE-2021-42640CRITICALCVSS 9.1EG 9.12022-02-02
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to reassign drivers for any printer.
- CVE-2021-42641HIGHCVSS 7.5EG 7.52022-02-02
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability that allows an unauthenticated attacker to disclose the username and email address of all users.
- CVE-2021-42712HIGHCVSS 7.8EG 7.82022-02-15
Splashtop Streamer through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-42713HIGHCVSS 7.8EG 7.82022-02-15
Splashtop Remote Client (Personal Edition) through 3.4.6.1 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-42714HIGHCVSS 7.8EG 7.82022-02-15
Splashtop Remote Client (Business Edition) through 3.4.8.3 creates a Temporary File in a Directory with Insecure Permissions.
- CVE-2021-42748MEDIUMCVSS 5.3EG 5.32022-01-10
In Beaver Builder through 2.5.0.3, attackers can bypass the visibility controls protection mechanism via the REST API.
- CVE-2021-42749MEDIUMCVSS 5.3EG 5.32022-01-10
In Beaver Themer, attackers can bypass conditional logic controls (for hiding content) when viewing the post archives. Exploitation requires that a Themer layout is applied to the archives, and that the post excerpt field is not set.
- CVE-2021-43039MEDIUMCVSS 6.5EG 6.52021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The Samba file sharing service allowed anonymous read/write access.
- CVE-2021-43043MEDIUMCVSS 6.5EG 6.52021-12-06
An issue was discovered in Kaseya Unitrends Backup Appliance before 10.5.5. The apache user could read arbitrary files such as /etc/shadow by abusing an insecure Sudo rule.
Map vulnerabilities like CWE-668 to your infrastructure
EchelonGraph correlates every CVE — across CWE-668 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →