CWE-639

High likelihood

Authorization Bypass Through User-Controlled Key

Parent: CWE-863 - Incorrect Authorization

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

1,811 vulnerabilities with CWE-639
CVE-2024-43239 MEDIUM
Masteriyo - LMS <1.11.4 - Auth Bypass
CVSS 4.3
CVE-2024-42464 MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-42463 MEDIUM
upKeeper Manager <5.1.9 - Auth Bypass
CVSS 6.5
CVE-2024-27730 CRITICAL
Friendica 2023.12 - Authorization Bypass and Remote Code Execution via Calendar Event cid Parameter
CVSS 9.8
CVE-2024-6534 MEDIUM
Directus v10.13.0 - Privilege Escalation
CVSS 4.3
CVE-2024-21981 MEDIUM
AMD Secure Processor - Info Disclosure
CVSS 5.7
CVE-2024-39642 MEDIUM
ThimPress LearnPress <4.2.6.8.2 - Auth Bypass
CVSS 6.5
CVE-2024-7658 MEDIUM
projectsend <r1605 - Info Disclosure
CVSS 5.3
CVE-2024-3035 MEDIUM
GitLab 8.12-17.0.5, 17.1-17.1.3, 17.2-17.2.1 - Authorization Bypass via LFS Token
CVSS 6.8
CVE-2024-6357 MEDIUM
OpenText ArcSight Intelligence - Info Disclosure
CVSS 6.3
CVE-2024-7438 MEDIUM
SimpleMachines SMF 2.1.4 - Improper Control of Resource Identifiers
CVSS 4.3
CVE-2024-7437 MEDIUM
SimpleMachines SMF 2.1.4 - Improper Control of Resource Identifiers
CVSS 5.4
CVE-2024-41254 MEDIUM
litestream < 0.3.13 - Man-in-the-Middle Attack via Insecure SSH Host Key Verification
CVSS 5.3
CVE-2024-38701 MEDIUM
Academy LMS < 2.0.4 - Authorization Bypass Through User-Controlled Key
CVSS 4.3
CVE-2024-34457 MEDIUM
Apache StreamPark < 2.1.4 - Authorization Bypass via User Token
CVSS 6.5
CVE-2024-5977 MEDIUM
GiveWP <= 3.13.0 - Authenticated IDOR via 'handleRequest'
CVSS 5.4
CVE-2024-5619 CRITICAL
PruvaSoft Informatics Apinizer Mgmt Console <2024.05.1 - Auth Bypass
CVSS 9.6
CVE-2024-38447 HIGH
NATO NCI ANET 3.4.1 - Info Disclosure
CVSS 8.1
CVE-2024-38446 MEDIUM
NATO NCI ANET 3.4.1 - Privilege Escalation
CVSS 6.5
CVE-2024-6410 MEDIUM
ProfileGrid <= 5.8.9 - Authenticated IDOR via pm_upload_image
CVSS 4.3
CVE-2024-39901 MEDIUM
OpenSearch Observability < 2.14 - Authorization Bypass via Private Tenant Resource Access
CVSS 4.2
CVE-2024-39900 MEDIUM
OpenSearch Observability < 2.14 - Authorization Bypass via Private Tenant Resource Access
CVSS 5.4
CVE-2024-39897 MEDIUM
Zot <2.1.0 - Unauthorized Blob Read via Dedupe Cache
CVSS 4.3
CVE-2024-21759 MEDIUM
FortiPortal 7.0.0-7.0.6 and 7.2.0 - Authorization Bypass via HTTP/HTTPS Requests
CVSS 4.3
CVE-2024-4341 MEDIUM
Extreme XDS < 3928 - Authorization Bypass via User-Controlled Key
CVSS 6.5
Details
Vulnerabilities 1,811
Exploit Likelihood High