CWE-863— Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.— MITRE CWE catalog
4,112 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-863page 29 of 83
- CVE-2022-1309CRITICALCVSS 9.6EG 9.62022-07-25
Insufficient policy enforcement in developer tools in Google Chrome prior to 100.0.4896.88 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
- CVE-2022-1365MEDIUMCVSS 6.5EG 6.52022-04-15
Exposure of Private Personal Information to an Unauthorized Actor in GitHub repository lquixada/cross-fetch prior to 3.1.5.
- CVE-2022-1401HIGHCVSS 6.9EG 7.52022-08-17
Improper Access Control vulnerability in the /Exago/WrImageResource.adx route as used in Device42 Asset Management Appliance allows an unauthenticated attacker to read sensitive server files with root permissions. This issue affects: Devic…
- CVE-2022-1417MEDIUMCVSS 4.3EG 4.32022-05-10
Improper access control in GitLab CE/EE affecting all versions starting from 8.12 before 14.8.6, all versions starting from 14.9 before 14.9.4, and all versions starting from 14.10 before 14.10.1 allows non-project members to access conten…
- CVE-2022-1423HIGHCVSS 7.1EG 8.82022-05-19
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor wi…
- CVE-2022-1460MEDIUMCVSS 6.1EG 6.12022-05-11
An issue has been discovered in GitLab affecting all versions starting from 9.2 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not performing correct authorizations…
- CVE-2022-1466MEDIUMCVSS 6.5EG 6.52022-04-26
Due to improper authorization, Red Hat Single Sign-On is vulnerable to users performing actions that they should not be allowed to perform. It was possible to add users to the master realm even though no respective permission was granted.
- CVE-2022-1482MEDIUMCVSS 6.5EG 6.52022-07-26
Inappropriate implementation in WebGL in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-1499MEDIUMCVSS 6.3EG 6.32022-07-26
Inappropriate implementation in WebAuthentication in Google Chrome prior to 101.0.4951.41 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
- CVE-2022-1502MEDIUMCVSS 4.3EG 4.32022-05-04
Permissions were not properly verified in the API on projects using version control in Git. This allowed projects to be modified by users with only ProjectView permissions.
- CVE-2022-1545MEDIUMCVSS 4.3EG 4.32022-05-11
It was possible to disclose details of confidential notes created via the API in Gitlab CE/EE affecting all versions from 13.2 prior to 14.8.6, 14.9 prior to 14.9.4, and 14.10 prior to 14.10.1 if an unauthorised project member was tagged i…
- CVE-2022-1553MEDIUMCVSS 4.9EG 4.92022-05-16
Leaking password protected articles content due to improper access control in GitHub repository publify/publify prior to 9.2.8. Attackers can leverage this vulnerability to view the contents of any password-protected article present on the…
- CVE-2022-1589HIGHCVSS 7.5EG 7.52022-05-30
The Change wp-admin login WordPress plugin before 1.1.0 does not properly check for authorisation and is also missing CSRF check when updating its settings, which could allow unauthenticated users to change the settings. The attacked could…
- CVE-2022-1631HIGHCVSS 8.8EG 8.82022-05-09
Users Account Pre-Takeover or Users Account Takeover. in GitHub repository microweber/microweber prior to 1.2.15. Victim Account Take Over. Since, there is no email confirmation, an attacker can easily create an account in the application …
- CVE-2022-1706MEDIUMCVSS 6.5EG 6.52022-05-17
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The hi…
- CVE-2022-1746HIGHCVSS 7.6EG 7.62022-06-24
The authentication mechanism used by poll workers to administer voting using the tested version of Dominion Voting Systems ImageCast X can expose cryptographic secrets used to protect election information. An attacker could leverage this v…
- CVE-2022-1753MEDIUMCVSS 5.4EG 5.42022-05-17
A vulnerability, which was classified as critical, was found in WoWonder. Affected is the file /requests.php which is responsible to handle group messages. The manipulation of the argument group_id allows posting messages in other groups. …
- CVE-2022-1801HIGHCVSS 7.5EG 7.52022-06-20
The Very Simple Contact Form WordPress plugin before 11.6 exposes the solution to the captcha in the rendered contact form, both as hidden input fields and as plain text in the page, making it very easy for bots to bypass the captcha check…
- CVE-2022-1874HIGHCVSS 8.8EG 8.82022-07-27
Insufficient policy enforcement in Safe Browsing in Google Chrome on Mac prior to 102.0.5005.61 allowed a remote attacker to bypass downloads protection policy via a crafted HTML page.
- CVE-2022-1935MEDIUMCVSS 6.5EG 6.52022-06-06
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Projec…
- CVE-2022-1936MEDIUMCVSS 6.5EG 6.52022-06-06
Incorrect authorization in GitLab EE affecting all versions from 12.0 before 14.9.5, all versions starting from 14.10 before 14.10.4, all versions starting from 15.0 before 15.0.1 allowed an attacker already in possession of a valid Projec…
- CVE-2022-1944HIGHCVSS 5.4EG 7.12022-06-06
When the feature is configured, improper authorization in the Interactive Web Terminal in GitLab CE/EE affecting all versions from 11.3 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows users with the Developer role …
- CVE-2022-1949HIGHCVSS 7.5EG 7.52022-06-02
An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass. This may allow any …
- CVE-2022-1981LOWCVSS 2.7EG 2.72022-07-01
An issue has been discovered in GitLab EE affecting all versions starting from 12.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1. In GitLab, if a group enables the setting to restrict access to users belonging to specif…
- CVE-2022-1983MEDIUMCVSS 6.5EG 6.52022-07-01
Incorrect authorization in GitLab EE affecting all versions from 10.7 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allowed an attacker already in possession of a valid Deploy Key or a Deploy Token to misuse it from any…
- CVE-2022-20002HIGHCVSS 7.8EG 7.82022-03-30
In incfs, there is a possible way of mounting on arbitrary paths due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P…
- CVE-2022-2019HIGHCVSS 7.3EG 7.52022-06-09
A vulnerability classified as critical was found in SourceCodester Prison Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /classes/Users.php?f=save of the component New User Creation. The manip…
- CVE-2022-20217MEDIUMCVSS 6.5EG 6.52022-07-13
There is a unauthorized broadcast in the SprdContactsProvider. A third-party app could use this issue to delete Fdn contact.Product: AndroidVersions: Android SoCAndroid ID: A-232441378
- CVE-2022-20321LOWCVSS 3.3EG 3.32022-08-12
In Settings, there is a possible way for an application without permissions to read content of WiFi QR codes due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.…
- CVE-2022-20323MEDIUMCVSS 5.5EG 5.52022-08-12
In PackageManager, there is a possible package installation disclosure due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitatio…
- CVE-2022-20326MEDIUMCVSS 5.5EG 5.52022-08-12
In Telephony, there is a possible disclosure of SIM identifiers due to a missing permission check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Produ…
- CVE-2022-20558LOWCVSS 3.3EG 3.32022-12-16
In registerReceivers of DeviceCapabilityListener.java, there is a possible way to change preferred TTY mode due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User …
- CVE-2022-20572MEDIUMCVSS 6.7EG 6.72022-12-16
In verity_target of dm-verity-target.c, there is a possible way to modify read-only files due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not …
- CVE-2022-20762HIGHCVSS 7.8EG 7.82022-04-06
A vulnerability in the Common Execution Environment (CEE) ConfD CLI of Cisco Ultra Cloud Core - Subscriber Microservices Infrastructure (SMI) software could allow an authenticated, local attacker to escalate privileges on an affected devic…
- CVE-2022-20777CRITICALCVSS 9.9EG 9.92022-05-04
Multiple vulnerabilities in Cisco Enterprise NFV Infrastructure Software (NFVIS) could allow an attacker to escape from the guest virtual machine (VM) to the host machine, inject commands that execute at the root level, or leak system data…
- CVE-2022-20859HIGHCVSS 6.5EG 8.82022-07-06
A vulnerability in the Disaster Recovery framework of Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), and Cisco Unity Connection could allow an authen…
- CVE-2022-20928MEDIUMCVSS 5.8EG 5.82022-11-15
A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish …
- CVE-2022-20942MEDIUMCVSS 6.5EG 6.52022-11-04
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authent…
- CVE-2022-2095MEDIUMCVSS 4.3EG 4.32022-08-05
An improper access control check in GitLab CE/EE affecting all versions starting from 13.7 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious authenticated user to…
- CVE-2022-21140MEDIUMCVSS 5.5EG 5.52022-08-18
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi products may allow a privileged user to potentially enable information disclosure via local access.
- CVE-2022-21141CRITICALCVSS 10.0EG 10.02022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain a…
- CVE-2022-21153MEDIUMCVSS 5.5EG 5.52022-02-09
Improper access control in the Intel(R) Capital Global Summit Android application may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2022-21157MEDIUMCVSS 5.5EG 5.52022-02-09
Improper access control in the Intel(R) Smart Campus Android application before version 6.1 may allow authenticated user to potentially enable information disclosure via local access.
- CVE-2022-21174HIGHCVSS 7.8EG 7.82022-02-09
Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access.
- CVE-2022-21196CRITICALCVSS 10.0EG 10.02022-02-18
MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An att…
- CVE-2022-21225HIGHCVSS 8.0EG 8.02022-08-18
Improper neutralization in the Intel(R) Data Center Manager software before version 4.1 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
- CVE-2022-2155HIGHCVSS 5.7EG 7.12023-01-12
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports fe…
- CVE-2022-21678MEDIUMCVSS 4.3EG 4.32022-01-13
Discourse is an open source discussion platform. Prior to version 2.8.0.beta11 in the `tests-passed` branch, version 2.8.0.beta11 in the `beta` branch, and version 2.7.13 in the `stable` branch, the bios of users who made their profiles pr…
- CVE-2022-21701MEDIUMCVSS 5.0EG 5.02022-01-19
Istio is an open platform to connect, manage, and secure microservices. In versions 1.12.0 and 1.12.1 Istio is vulnerable to a privilege escalation attack. Users who have `CREATE` permission for `gateways.gateway.networking.k8s.io` objects…
- CVE-2022-21706HIGHCVSS 7.2EG 7.22022-02-26
Zulip is an open-source team collaboration tool with topic-based threading. Zulip Server version 2.0.0 and above are vulnerable to insufficient access control with multi-use invitations. A Zulip Server deployment which hosts multiple organ…
Map vulnerabilities like CWE-863 to your infrastructure
EchelonGraph correlates every CVE — across CWE-863 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →