The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.
85 vulnerabilities with CWE-1220
CVE-2024-52799
HIGH
Argo Workflows Helm Chart <0.44.0 - Excessive Pod Exec Privileges
CVSS 8.2
CVE-2024-43604
MEDIUM
Outlook for Android - Privilege Escalation
CVSS 5.7
CVE-2024-8927
HIGH
PHP <8.1.30, 8.2.*<8.2.24, 8.3.*<8.3.12 - Code Injection
CVSS 7.5
CVE-2024-6867
MEDIUM
lunary-ai/lunary <a761d833 - Info Disclosure
CVSS 6.5
CVE-2024-42365
HIGH
Asterisk < 18.24.2 - Remote Code Execution
CVSS 7.4
CVE-2024-39324
LOW
ai-admin-graphql 2022.04.1-2022.10.9 - Insufficient Access Control via GraphQL API
CVSS 3.8
CVE-2024-39323
HIGH
ai-admin-graphql 2022.04.1-2022.10.9, 2023.04.1-2023.10.5, 2024.04.1-2024.04.5 - Improper Access Control
CVSS 7.1
CVE-2024-5389
HIGH
lunary < 1.4.9 - Insufficient Granularity of Access Control for Dataset Prompts
CVSS 8.1
CVE-2024-29200
MEDIUM
Kimai < 2.13.0 - Insufficient Access Control via API Timesheet Endpoint
CVSS 6.8
CVE-2024-26246
LOW
Microsoft Edge < 122.0.2365.92 - Security Feature Bypass
CVSS 3.9
CVE-2024-2412
MEDIUM
Heimavista Rpage and Epage - User Registration Bypass
CVSS 5.3
CVE-2023-31343
HIGH
AMD EPYC 7003 Processors - Authenticated Arbitrary Code Execution via SMM Handler Input Validation
CVSS 7.5
CVE-2023-31342
HIGH
AMD EPYC 7003 Processors - Arbitrary Code Execution via SMM Handler Input Validation
CVSS 7.5
CVE-2023-45217
HIGH
Intel Power Gadget < 3.6.0 - Authenticated Privilege Escalation via Local Access
CVSS 8.8
CVE-2023-40070
HIGH
Intel Power Gadget for macOS - Authenticated Privilege Escalation via Local Access
CVSS 8.8
CVE-2023-43040
MEDIUM
IBM Spectrum Fusion HCI 2.5.2-2.7.2 - Privilege Escalation
CVSS 6.5
CVE-2023-32259
MEDIUM
OpenText SMAX/AMX <2022.11 - Privilege Escalation
CVSS 6.5
CVE-2023-6725
MEDIUM
OpenStack Designate - Info Disclosure
CVSS 5.5
CVE-2023-50713
MEDIUM
Speckle Server <2.17.6 - Auth Bypass
CVSS 6.5
CVE-2023-44285
HIGH
Dell PowerProtect DD <7.13.0.10-6.2.1.110 - Privilege Escalation
CVSS 7.8
CVE-2023-4456
MEDIUM
openshift-logging LokiStack - Privilege Escalation
CVSS 5.7
CVE-2023-39418
LOW
PostgreSQL 15.0-15.3 - Insufficient Granularity of Access Control via MERGE Command
CVSS 3.1
CVE-2023-33127
HIGH
.NET 6.0.0-6.0.19 and Visual Studio 2022 < 17.0.23 - Elevation of Privilege
CVSS 8.1
CVE-2023-3227
MEDIUM
fossbilling/fossbilling <0.5.0 - Info Disclosure
CVSS 5.7
CVE-2023-0205
MEDIUM
NVIDIA ConnectX-5, ConnectX-6, and ConnectX6-DX < 35.1012 - Denial of Service via Insufficient Access Control
CVSS 5.0
Details
Vulnerabilities
85