CWE-862— Missing Authorization
7,602 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-862page 10 of 153
- CVE-2020-13316MEDIUMCVSS 5.4EG 5.42020-09-14
A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab was not validating a Deploy-Token and allowed a disabled repository be accessible via a git command line.
- CVE-2020-13319MEDIUMCVSS 4.3EG 4.32020-09-30
An issue has been discovered in GitLab affecting versions prior to 13.1.2, 13.0.8 and 12.10.13. Missing permission check for adding time spent on an issue.
- CVE-2020-13422HIGHCVSS 8.1EG 8.12021-04-06
OpenIAM before 4.2.0.3 does not verify if a user has permissions to perform /webconsole/rest/api/* administrative actions.
- CVE-2020-13425HIGHCVSS 7.1EG 7.12020-05-23
TrackR devices through 2020-05-06 allow attackers to trigger the Beep (aka alarm) feature, which will eventually cause a denial of service when battery capacity is exhausted.
- CVE-2020-13445HIGHCVSS 8.8EG 8.82020-06-10
In Liferay Portal before 7.3.2 and Liferay DXP 7.0 before fix pack 92, 7.1 before fix pack 18, and 7.2 before fix pack 6, the template API does not restrict user access to sensitive objects, which allows remote authenticated users to execu…
- CVE-2020-13464MEDIUMCVSS 4.2EG 4.22020-08-31
The flash memory readout protection in China Key Systems & Integrated Circuit CKS32F103 devices allows physical attackers to extract firmware via the debug interface by utilizing the CPU or DMA module.
- CVE-2020-13512HIGHCVSS 8.8EG 8.82020-12-18
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. Using the IRP 0x9c40a0d8 gives a …
- CVE-2020-13513HIGHCVSS 8.8EG 8.82020-12-18
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. Using the IRP 0x9c40a0dc gives a …
- CVE-2020-13514HIGHCVSS 8.8EG 8.82020-12-18
A privilege escalation vulnerability exists in the WinRing0x64 Driver Privileged I/O Write IRPs functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. Using the IRP 0x9c40a0e0 gives a …
- CVE-2020-13515HIGHCVSS 8.8EG 8.82020-12-18
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c40a148 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause an adversary to obtain elevated privileges. An attacker can send a…
- CVE-2020-13519HIGHCVSS 8.8EG 8.82020-12-18
A privilege escalation vulnerability exists in the WinRing0x64 Driver IRP 0x9c402088 functionality of NZXT CAM 4.8.0. A specially crafted I/O request packet (IRP) can cause increased privileges. An attacker can send a malicious IRP to trig…
- CVE-2020-13523LOWCVSS 3.3EG 3.32020-08-04
An exploitable information disclosure vulnerability exists in SoftPerfect’s RAM Disk 4.1 spvve.sys driver. A specially crafted I/O request packet (IRP) can cause the disclosure of sensitive information. An attacker can send a malicious I…
- CVE-2020-13626MEDIUMCVSS 4.6EG 4.62020-10-09
OnePlus App Locker through 2020-10-06 allows physically proximate attackers to use Google Assistant to bypass an authorization check in order to send an SMS message when the SMS application is locked.
- CVE-2020-13794MEDIUMCVSS 4.3EG 4.32020-09-30
Harbor 1.9.* 1.10.* and 2.0.* allows Exposure of Sensitive Information to an Unauthorized Actor.
- CVE-2020-13850HIGHCVSS 7.5EG 7.52020-06-11
Artica Pandora FMS 7.44 has inadequate access controls on a web folder.
- CVE-2020-13938MEDIUMCVSS 5.5EG 5.52021-06-10
Apache HTTP Server versions 2.4.0 to 2.4.46 Unprivileged local users can stop httpd on Windows
- CVE-2020-14001CRITICALCVSS 9.8EG 9.82020-07-17
The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string th…
- CVE-2020-14185MEDIUMCVSS 5.3EG 5.32020-10-15
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9…
- CVE-2020-14190HIGHCVSS 7.5EG 7.52020-11-25
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to achieve Regex Denial of Service via user-supplied regex in EyeQL. The affected versions are before version 4.8.4.
- CVE-2020-14191HIGHCVSS 7.5EG 7.52020-11-25
Affected versions of Atlassian Fisheye/Crucible allow remote attackers to impact the application's availability via a Denial of Service (DoS) vulnerability in the MessageBundleResource within Atlassian Gadgets. The affected versions are be…
- CVE-2020-14205MEDIUMCVSS 5.3EG 5.32020-12-08
The DiveBook plugin 1.1.4 for WordPress is prone to improper access control in the Log Dive form because it fails to perform authorization checks. An attacker may leverage this issue to manipulate the integrity of dive logs.
- CVE-2020-14213MEDIUMCVSS 5.4EG 5.42020-06-16
In Zammad before 3.3.1, a Customer has ticket access that should only be available to an Agent (e.g., read internal data, split, or merge).
- CVE-2020-14214MEDIUMCVSS 6.5EG 6.52020-06-16
Zammad before 3.3.1, when Domain Based Assignment is enabled, relies on a claimed e-mail address for authorization decisions. An attacker can register a new account that will have access to all tickets of an arbitrary Organization.
- CVE-2020-14306HIGHCVSS 8.8EG 8.82020-09-16
An incorrect access control flaw was found in the operator, openshift-service-mesh/istio-rhel8-operator all versions through 1.1.3. This flaw allows an attacker with a basic level of access to the cluster to deploy a custom gateway/pod to …
- CVE-2020-14491MEDIUMCVSS 6.5EG 6.52020-07-20
OpenClinic GA versions 5.09.02 and 5.89.05b do not properly check permissions before executing SQL queries, which may allow a low-privilege user to access privileged information.
- CVE-2020-14520HIGHCVSS 7.5EG 7.52020-07-31
The affected product is vulnerable to an information leak, which may allow an attacker to obtain sensitive information on the Ignition 8 (all versions prior to 8.0.13).
- CVE-2020-14944CRITICALCVSS 9.8EG 9.82020-06-22
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exp…
- CVE-2020-14969HIGHCVSS 7.5EG 7.52020-06-22
app/Model/Attribute.php in MISP 2.4.127 lacks an ACL lookup on attribute correlations. This occurs when querying the attribute restsearch API, revealing metadata about a correlating but unreachable attribute.
- CVE-2020-14971HIGHCVSS 7.8EG 7.82020-06-23
Pi-hole through 5.0 allows code injection in piholedhcp (the Static DHCP Leases section) by modifying Teleporter backup files and then restoring them. This occurs in settings.php. To exploit this, an attacker would request a backup of limi…
- CVE-2020-14978HIGHCVSS 8.1EG 8.12020-06-23
An issue was discovered in F-Secure SAFE 17.7 on macOS. Due to incorrect client version verification, an attacker can connect to a privileged XPC service, and execute privileged commands on the system. NOTE: the attacker needs to execute c…
- CVE-2020-14987HIGHCVSS 7.2EG 7.22021-03-11
An issue was discovered in Bloomreach Experience Manager (brXM) 4.1.0 through 14.2.2. It allows remote attackers to execute arbitrary code because there is a mishandling of the capability for administrators to write and run Groovy scripts …
- CVE-2020-15001MEDIUMCVSS 5.3EG 5.32020-07-09
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes…
- CVE-2020-15080MEDIUMCVSS 5.3EG 5.32020-07-02
In PrestaShop from version 1.7.4.0 and before version 1.7.6.6, some files should not be in the release archive, and others should not be accessible. The problem is fixed in version 1.7.6.6 A possible workaround is to make sure `composer.js…
- CVE-2020-15102MEDIUMCVSS 6.5EG 6.52020-07-21
In PrestaShop Dashboard Productions before version 2.1.0, there is improper authorization which enables an attacker to change the configuration. The problem is fixed in 2.1.0.
- CVE-2020-15109MEDIUMCVSS 5.3EG 5.32020-08-04
In solidus before versions 2.8.6, 2.9.6, and 2.10.2, there is an bility to change order address without triggering address validations. This vulnerability allows a malicious customer to craft request data with parameters that allow changin…
- CVE-2020-15245MEDIUMCVSS 4.3EG 4.32020-10-19
In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, change it to the mail another@domain.com and stay verified and enabled. This may lead to having accounts addressed to t…
- CVE-2020-15247MEDIUMCVSS 5.2EG 5.22020-11-23
October is a free, open-source, self-hosted CMS platform based on the Laravel PHP Framework. In October CMS from version 1.0.319 and before version 1.0.469, an authenticated backend user with the cms.manage_pages, cms.manage_layouts, or cm…
- CVE-2020-15251HIGHCVSS 7.7EG 7.72020-10-13
In the Channelmgnt plug-in for Sopel (a Python IRC bot) before version 1.0.3, malicious users are able to op/voice and take over a channel. This is an ACL bypass vulnerability. This plugin is bundled with MirahezeBot-Plugins with versions …
- CVE-2020-15337MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /registerCpe requests.
- CVE-2020-15338MEDIUMCVSS 5.3EG 5.32022-09-29
Zyxel CloudCNM SecuManager 3.1.0 and 3.1.1 has a "Use of GET Request Method With Sensitive Query Strings" issue for /cnr requests.
- CVE-2020-15349HIGHCVSS 7.8EG 7.82020-11-17
BinaryNights ForkLift 3.x before 3.4 has a local privilege escalation vulnerability because the privileged helper tool implements an XPC interface that allows file operations to any process (copy, move, delete) as root and changing permiss…
- CVE-2020-15360HIGHCVSS 7.8EG 7.82020-06-27
com.docker.vmnetd in Docker Desktop 2.3.0.3 allows privilege escalation because of a lack of client verification.
- CVE-2020-15408LOWCVSS 3.7EG 3.72020-07-28
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
- CVE-2020-15412MEDIUMCVSS 4.3EG 4.32020-06-30
An issue was discovered in MISP 2.4.128. app/Controller/EventsController.php lacks an event ACL check before proceeding to allow a user to send an event contact form.
- CVE-2020-15518HIGHCVSS 8.8EG 8.82020-07-03
VeeamFSR.sys in Veeam Availability Suite before 10 and Veeam Backup & Replication before 10 has no device object DACL, which allows unprivileged users to achieve total control over filesystem I/O requests.
- CVE-2020-15780MEDIUMCVSS 6.7EG 6.72020-07-15
An issue was discovered in drivers/acpi/acpi_configfs.c in the Linux kernel before 5.7.7. Injection of malicious ACPI tables via configfs could be used by attackers to bypass lockdown and secure boot restrictions, aka CID-75b0cea7bf30.
- CVE-2020-15943HIGHCVSS 8.1EG 8.12020-08-04
An issue was discovered in the Gantt-Chart module before 5.5.4 for Jira. Due to a missing privilege check, it is possible to read and write to the module configuration of other users. This can also be used to deliver an XSS payload to othe…
- CVE-2020-15958HIGHCVSS 8.6EG 8.62020-09-18
An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.
- CVE-2020-16022HIGHCVSS 8.8EG 8.82021-01-08
Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.
- CVE-2020-16027MEDIUMCVSS 6.5EG 6.52021-01-08
Insufficient policy enforcement in developer tools in Google Chrome prior to 87.0.4280.66 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from the user's disk via a craf…
Map vulnerabilities like CWE-862 to your infrastructure
EchelonGraph correlates every CVE — across CWE-862 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →