CWE-281
Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
337 vulnerabilities with CWE-281
CVE-2024-32020
LOW
Git <2.45.1-2.39.4 - Info Disclosure
CVSS 3.9
CVE-2024-4768
MEDIUM
Firefox <126, Firefox ESR <115.11, Thunderbird <115.11 - Privilege ...
CVSS 6.1
CVE-2024-33921
MEDIUM
ReviewX < 1.6.21 - Broken Access Control
CVSS 4.3
CVE-2024-32882
LOW
Wagtail 6.0.0-6.0.3 - Permission Bypass via FieldPanel Permission Argument
CVSS 2.7
CVE-2024-22405
MEDIUM
XADMaster <1.10.8 - Info Disclosure
CVSS 5.5
CVE-2024-1726
MEDIUM
Quarkus RESTEasy Reactive 3.8.0.CR1-3.8.0 - Denial of Service via JAX-RS Endpoint Serialization
CVSS 5.3
CVE-2024-23560
MEDIUM
HCL DevOps Deploy/HCL Launch - Privilege Escalation
CVSS 4.4
CVE-2024-3545
MEDIUM
Drevolutions Remote Desktop Manager <2024.1.20 - Info Disclosure
CVSS 4.3
CVE-2024-22177
LOW
OpenHarmony < 3.2.4 - Local Denial of Service via Permission Handling
CVSS 3.3
CVE-2024-29735
MEDIUM
Apache Airflow <2.8.3 - Privilege Escalation
CVSS 5.3
CVE-2024-30187
MEDIUM
Anope <2.0.15 - Privilege Escalation
CVSS 5.3
CVE-2024-28746
HIGH
Apache Airflow <2.8.3 - Info Disclosure
CVSS 8.1
CVE-2024-28152
MEDIUM
Jenkins Bitbucket Branch Source Plugin <866.vdea_7dcd3008e - Info D...
CVSS 6.3
CVE-2024-21816
MEDIUM
OpenHarmony <= 4.0.0 - Information Disclosure via Improper Permission Preservation
CVSS 4.0
CVE-2024-0674
MEDIUM
Lamassu Bitcoin ATM Douro 7.1 - Privilege Escalation
CVSS 6.3
CVE-2024-22404
MEDIUM
Nextcloud Files Zip <1.2.1-1.5.0 - Info Disclosure
CVSS 4.1
CVE-2024-22402
MEDIUM
Nextcloud Guests < 2.4.1 - Permissions Bypass via App Page Access
CVSS 5.4
CVE-2024-22401
MEDIUM
Nextcloud Guests <2.4.1-3.0.1 - Privilege Escalation
CVSS 4.1
CVE-2023-32199
MEDIUM
Rancher Manager - Privilege Escalation
CVSS 4.3
CVE-2023-42231
HIGH
Zucchetti HelpdeskAdvanced <= 11.0.33 - Incorrect Access Control
CVSS 8.1
CVE-2023-42228
HIGH
Zucchetti HelpdeskAdvanced <= 11.0.33 - Incorrect Access Control
CVSS 8.8
CVE-2023-42867
HIGH
GarageBand <10.4.9 - Privilege Escalation
CVSS 7.8
CVE-2023-25646
HIGH
ZTE ZXHN H388X Firmware - Unauthenticated Privilege Escalation via Serial Port Brute-Force
CVSS 7.1
CVE-2023-52542
MEDIUM
Huawei EMUI and HarmonyOS - Denial of Service via Permission Verification Bypass
CVSS 6.5
CVE-2023-49932
MEDIUM
Couchbase Server <7.2.4 - Auth Bypass
CVSS 5.4
Details
Vulnerabilities
337