CWE-281
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
329 vulnerabilities with CWE-281
CVE-2020-8634
HIGH
Wing FTP Server v6.2.3 - Privilege Escalation
CVSS 7.8
CVE-2020-9442
HIGH
OpenVPN Connect <3.1.0.361 - Privilege Escalation
CVSS 7.8
CVE-2020-7063
MEDIUM
PHP <7.2.28-7.3.15-7.4.3 - Info Disclosure
CVSS 5.5
CVE-2020-8633
MEDIUM
Zimbra Collaboration Suite <8.8.15.7 - Info Disclosure
CVSS 5.3
CVE-2020-8117
MEDIUM
Nextcloud Server <14.0.3 - Info Disclosure
CVSS 4.3
CVE-2019-14841
HIGH
Red Hat Decision Manager - Authenticated Privilege Escalation via Role Modification in Response Header
CVSS 8.8
CVE-2019-0233
HIGH
Apache Struts 2.0.0-2.5.20 - Denial of Service via File Upload Permission Override
CVSS 7.5
CVE-2019-20846
HIGH
Mattermost Server <5.18.0 - Info Disclosure
CVSS 7.5
CVE-2019-20843
HIGH
Mattermost Server <5.18.0-5.9.7 - Info Disclosure
CVSS 7.5
CVE-2019-15621
MEDIUM
Nextcloud Server 16.0.1 - Info Disclosure
CVSS 6.5
CVE-2019-13727
HIGH
Google Chrome < 79.0.3945.79 - Same Origin Policy Bypass via WebSocket
CVSS 8.8
CVE-2019-19620
LOW
SecureWorks Red Cloak Windows Agent <2.0.7.9 - Auth Bypass
CVSS 3.3
CVE-2019-18458
LOW
GitLab 10.5.0-12.4.0 - Insecure Permission Preservation
CVSS 2.7
CVE-2019-18457
HIGH
GitLab 11.8.0-12.4.0 - Insecure Permissions in Security Token Handling
CVSS 8.8
CVE-2019-13682
HIGH
Google Chrome <77.0.3865.75 - Auth Bypass
CVSS 8.8
CVE-2019-13668
HIGH
Google Chrome <77.0.3865.75 - Info Disclosure
CVSS 7.4
CVE-2019-16539
MEDIUM
Jenkins Support Core Plugin <2.63 - Privilege Escalation
CVSS 6.5
CVE-2019-14226
HIGH
OX App Suite <7.10.2 - Info Disclosure
CVSS 8.1
CVE-2019-0073
MEDIUM
Junos OS Insecure PKI Key Export Permissions
CVSS 6.6
CVE-2019-14956
MEDIUM
JetBrains YouTrack <2019.2.53938 - Info Disclosure
CVSS 4.3
CVE-2019-11748
MEDIUM
Firefox < 69.0 and Firefox ESR < 68.1.0 - Improper Preservation of Permissions in WebRTC
CVSS 6.5
CVE-2019-6791
MEDIUM
GitLab <11.5.8-11.7.1 - Privilege Escalation
CVSS 6.5
CVE-2019-6995
MEDIUM
GitLab <11.5.8-11.7.1 - Info Disclosure
CVSS 6.5
CVE-2018-12989
MEDIUM
Pearson VUE Certiport Console <2018-06-26 - Privilege Escalation
CVSS 6.7
CVE-2018-3762
MEDIUM
Nextcloud Server < 12.0.8 - Improper Access Control via File Preview Request
CVSS 4.3
Details
Vulnerabilities
329