CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2020-15113 MEDIUM
etcd <3.3.23, 3.4.10 - Info Disclosure
CVSS 5.7
CVE-2020-8190 HIGH
Citrix Application Delivery Controller Firmware < 10.5-70.18 - Privilege Escalation
CVSS 7.5
CVE-2020-14958 MEDIUM
Gogs 0.11.91 - Improper Preservation of Permissions in Email Ownership Check
CVSS 6.5
CVE-2020-13763 HIGH
Joomla! < 3.9.19 - Unauthenticated HTML Injection via Global Textfilter Configuration
CVSS 7.5
CVE-2020-13230 MEDIUM
Cacti < 1.2.11 - Improper Preservation of Permissions
CVSS 4.3
CVE-2020-2025 HIGH
Kata Containers runtime < 1.11.0 - Unauthenticated Guest-to-Host Filesystem Overwrite via Image Persistence
CVSS 8.8
CVE-2020-9781 MEDIUM
iPadOS < 13.4 - Unintended Website Permission Grant via Permission Prompt Retention
CVSS 5.3
CVE-2020-10083 CRITICAL
GitLab 12.7-12.8.1 - Insecure Permissions
CVSS 9.1
CVE-2020-8634 HIGH
Wing FTP Server v6.2.3 - Privilege Escalation
CVSS 7.8
CVE-2020-9442 HIGH
OpenVPN Connect <3.1.0.361 - Privilege Escalation
CVSS 7.8
CVE-2020-7063 MEDIUM
PHP <7.2.28-7.3.15-7.4.3 - Info Disclosure
CVSS 5.5
CVE-2020-8633 MEDIUM
Zimbra Collaboration Suite <8.8.15.7 - Info Disclosure
CVSS 5.3
CVE-2020-8117 MEDIUM
Nextcloud Server <14.0.3 - Info Disclosure
CVSS 4.3
CVE-2019-14841 HIGH
Red Hat Decision Manager - Authenticated Privilege Escalation via Role Modification in Response Header
CVSS 8.8
CVE-2019-0233 HIGH
Apache Struts 2.0.0-2.5.20 - Denial of Service via File Upload Permission Override
CVSS 7.5
CVE-2019-20846 HIGH
Mattermost Server <5.18.0 - Info Disclosure
CVSS 7.5
CVE-2019-20843 HIGH
Mattermost Server <5.18.0-5.9.7 - Info Disclosure
CVSS 7.5
CVE-2019-15621 MEDIUM
Nextcloud Server 16.0.1 - Info Disclosure
CVSS 6.5
CVE-2019-13727 HIGH
Google Chrome < 79.0.3945.79 - Same Origin Policy Bypass via WebSocket
CVSS 8.8
CVE-2019-19620 LOW
SecureWorks Red Cloak Windows Agent <2.0.7.9 - Auth Bypass
CVSS 3.3
CVE-2019-18458 LOW
GitLab 10.5.0-12.4.0 - Insecure Permission Preservation
CVSS 2.7
CVE-2019-18457 HIGH
GitLab 11.8.0-12.4.0 - Insecure Permissions in Security Token Handling
CVSS 8.8
CVE-2019-13682 HIGH
Google Chrome <77.0.3865.75 - Auth Bypass
CVSS 8.8
CVE-2019-13668 HIGH
Google Chrome <77.0.3865.75 - Info Disclosure
CVSS 7.4
CVE-2019-16539 MEDIUM
Jenkins Support Core Plugin <2.63 - Privilege Escalation
CVSS 6.5
Details
Vulnerabilities 337