CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

321 vulnerabilities with CWE-281
CVE-2024-27888 MEDIUM
macOS Sonoma <14.4 - Info Disclosure
CVSS 5.5
CVE-2024-39902 MEDIUM
Tuleap <15.10.99.128-15.9-8 - Info Disclosure
CVSS 4.8
CVE-2024-29080 MEDIUM
HP Display Control - Privilege Escalation
CVSS 6.5
CVE-2024-2819 MEDIUM
Hitachi Ops Center Common Services <11.0.2-00 - Privilege Escalation
CVSS 5.1
CVE-2024-36532 CRITICAL
kruise <1.6.2 - Privilege Escalation
CVSS 10.0
CVE-2024-38361 LOW
SpiceDB - Info Disclosure
CVSS 3.7
CVE-2024-37882 HIGH
Nextcloud Server < 26.0.13 - Improper Access Control
CVSS 8.1
CVE-2024-3291 HIGH
Nessus Agent <10.6.4 - Privilege Escalation
CVSS 7.8
CVE-2024-3289 HIGH
Nessus <10.7.3 - Privilege Escalation
CVSS 7.8
CVE-2024-32020 LOW
Git <2.45.1-2.39.4 - Info Disclosure
CVSS 3.9
CVE-2024-4768 MEDIUM
Firefox <126, Firefox ESR <115.11, Thunderbird <115.11 - Privilege ...
CVSS 6.1
CVE-2024-33921 MEDIUM
ReviewX <1.6.21 - Info Disclosure
CVSS 4.3
CVE-2024-32882 LOW
Wagtail - Auth Bypass
CVSS 2.7
CVE-2024-22405 MEDIUM
XADMaster <1.10.8 - Info Disclosure
CVSS 5.5
CVE-2024-1726 MEDIUM
Io.quarkus.resteasy.reactive Resteasy-reactive - Denial of Service
CVSS 5.3
CVE-2024-23560 MEDIUM
HCL DevOps Deploy/HCL Launch - Privilege Escalation
CVSS 4.4
CVE-2024-3545 MEDIUM
Drevolutions Remote Desktop Manager <2024.1.20 - Info Disclosure
CVSS 4.3
CVE-2024-22177 LOW
OpenHarmony <v3.2.4 - DoS
CVSS 3.3
CVE-2024-29735 MEDIUM
Apache Airflow <2.8.3 - Privilege Escalation
CVSS 5.3
CVE-2024-30187 MEDIUM
Anope <2.0.15 - Privilege Escalation
CVSS 5.3
CVE-2024-28746 HIGH
Apache Airflow <2.8.3 - Info Disclosure
CVSS 8.1
CVE-2024-28152 MEDIUM
Jenkins Bitbucket Branch Source Plugin <866.vdea_7dcd3008e - Info D...
CVSS 6.3
CVE-2024-21816 MEDIUM
Openatom Openharmony - Information Disclosure
CVSS 4.0
CVE-2024-0674 MEDIUM
Lamassu Bitcoin ATM Douro 7.1 - Privilege Escalation
CVSS 6.3
CVE-2024-22404 MEDIUM
Nextcloud Files Zip <1.2.1-1.5.0 - Info Disclosure
CVSS 4.1
Details
Vulnerabilities 321