CWE-281

Improper Preservation of Permissions

Parent: CWE-732 - Incorrect Permission Assignment for Critical Resource

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

337 vulnerabilities with CWE-281
CVE-2022-36062 HIGH
Grafana <8.5.13, 9.0.9, 9.1.6 - Privilege Escalation
CVSS 7.6
CVE-2022-38577 HIGH
ProcessMaker <3.5.4 - Privilege Escalation
CVSS 8.8
CVE-2022-36102 MEDIUM
Shopware < 5.7.15 - ACL Bypass via Backend Admin Controller Notation
CVSS 6.3
CVE-2022-2787 MEDIUM
schroot < 1.6.13 - Denial of Service via Chroot Session Name Rules
CVSS 4.3
CVE-2022-31237 LOW
Dell PowerScale OneFS <9.2.1.12 & 9.3.0.5 - Info Disclosure
CVSS 3.3
CVE-2022-31262 HIGH
GOG Galaxy 2.0.46 - Privilege Escalation
CVSS 7.8
CVE-2022-22472 HIGH
IBM Spectrum Protect Plus - Auth Bypass
CVSS 8.8
CVE-2022-32969 MEDIUM
MetaMask <10.11.3 - Info Disclosure
CVSS 5.9
CVE-2022-31096 MEDIUM
Discourse < 2.8.4 - Authenticated Permission Bypass via Invite Email Validation
CVSS 5.7
CVE-2022-31755 MEDIUM
Communication Module - Privilege Escalation
CVSS 5.5
CVE-2022-29594 HIGH
eG Agent <7.2 - Privilege Escalation
CVSS 7.8
CVE-2022-1227 HIGH
Podman < 4.0.0 - Privilege Escalation via Malicious Image in 'podman top' Command
CVSS 8.8
CVE-2022-24428 MEDIUM
Dell PowerScale OneFS - Privilege Escalation
CVSS 6.3
CVE-2022-0330 HIGH
Linux kernel's GPU i915 - Memory Corruption
CVSS 7.8
CVE-2022-22650 MEDIUM
macOS 10.15-10.15.6 and 11.6-11.6.4 - Unprotected User Data Exposure via Plugin Permission Inheritance
CVSS 5.5
CVE-2022-24618 HIGH
Heimdal Premium Security <2.5.395 - Privilege Escalation
CVSS 7.8
CVE-2022-21203 HIGH
Intel(R) Quartus(R) Prime <21.1 - Privilege Escalation
CVSS 7.8
CVE-2021-33990 CRITICAL
Liferay Portal 6.2.5 - OS Command Injection via File Upload Request
CVSS 9.8
CVE-2021-45446 MEDIUM
Hitachi Vantara Pentaho Business Analytics Server <9.2.0.2-8.3.0.25...
CVSS 5.0
CVE-2021-3414 HIGH
Red Hat Satellite - Improper Preservation of Permissions
CVSS 8.1
CVE-2021-35079 MEDIUM
Qualcomm APQ8053 and Multiple Snapdragon Firmware - Information Disclosure via Telephony Service API
CVSS 6.2
CVE-2021-3523 HIGH
3Scale APICast < 2.11.0 - Security Restriction Bypass via Connection Reuse
CVSS 7.5
CVE-2021-43708 MEDIUM
Titus Classification Suite <18.8.1910.140 - Info Disclosure
CVSS 5.5
CVE-2021-3847 HIGH
Linux Kernel OverlayFS - Privilege Escalation
CVSS 7.8
CVE-2021-39704 HIGH
Android - Local Privilege Escalation via NotificationManagerService Permissions Bypass
CVSS 7.8
Details
Vulnerabilities 337