CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

329 vulnerabilities with CWE-281
CVE-2024-23464 HIGH
Zscaler Client Connector <4.2.1 - Privilege Escalation
CVSS 7.2
CVE-2024-33892 HIGH
Cosy+ <21.2s10, <22.1s3 - Info Disclosure
CVSS 7.5
CVE-2024-40828 HIGH
macOS 12.0-12.7.5 13.0-13.6.7 14.0-14.5 - Privilege Escalation to Root
CVSS 7.8
CVE-2024-40824 MEDIUM
iPadOS < 17.6 - Privacy Preference Bypass via Improper Permission Preservation
CVSS 5.5
CVE-2024-40821 HIGH
macOS 12.0-12.7.5, <13.6.8, <14.6 - Unprotected User Data Exposure via Third-Party App Extension Sandbox Bypass
CVSS 7.1
CVE-2024-40811 MEDIUM
macOS Sonoma <14.6 - Info Disclosure
CVSS 5.5
CVE-2024-40805 HIGH
watchOS 10.6-macOS Sonoma 14.6-iOS 17.6-iPadOS 17.6-tvOS 17.6 - Pri...
CVSS 7.1
CVE-2024-40800 MEDIUM
macOS 12.0-12.7.5, 13.0-13.6.7, 14.0-14.5 - Unprotected User Data Exposure via Input Validation Issue
CVSS 5.5
CVE-2024-27888 MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 5.5
CVE-2024-39902 MEDIUM
Tuleap <15.10.99.128-15.9-8 - Info Disclosure
CVSS 4.8
CVE-2024-29080 MEDIUM
HP Display Control - Privilege Escalation
CVSS 6.5
CVE-2024-2819 MEDIUM
Hitachi Ops Center Common Services <11.0.2-00 - Privilege Escalation
CVSS 5.1
CVE-2024-36532 CRITICAL
kruise <1.6.2 - Privilege Escalation
CVSS 10.0
CVE-2024-38361 LOW
Spicedb < 1.33.1 - Incorrect Permission Resolution via Exclusion Dispatcher
CVSS 3.7
CVE-2024-37882 HIGH
Nextcloud Server 23.0.0-23.0.12.16 and 26.0.0-26.0.12 - Improper Access Control via Share Permission Escalation
CVSS 8.1
CVE-2024-3291 HIGH
Nessus Agent <10.6.4 - Privilege Escalation
CVSS 7.8
CVE-2024-3289 HIGH
Nessus <10.7.3 - Privilege Escalation
CVSS 7.8
CVE-2024-32020 LOW
Git <2.45.1-2.39.4 - Info Disclosure
CVSS 3.9
CVE-2024-4768 MEDIUM
Firefox <126, Firefox ESR <115.11, Thunderbird <115.11 - Privilege ...
CVSS 6.1
CVE-2024-33921 MEDIUM
ReviewX < 1.6.21 - Broken Access Control
CVSS 4.3
CVE-2024-32882 LOW
Wagtail 6.0.0-6.0.3 - Permission Bypass via FieldPanel Permission Argument
CVSS 2.7
CVE-2024-22405 MEDIUM
XADMaster <1.10.8 - Info Disclosure
CVSS 5.5
CVE-2024-1726 MEDIUM
Quarkus RESTEasy Reactive 3.8.0.CR1-3.8.0 - Denial of Service via JAX-RS Endpoint Serialization
CVSS 5.3
CVE-2024-23560 MEDIUM
HCL DevOps Deploy/HCL Launch - Privilege Escalation
CVSS 4.4
CVE-2024-3545 MEDIUM
Drevolutions Remote Desktop Manager <2024.1.20 - Info Disclosure
CVSS 4.3
Details
Vulnerabilities 329