CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

732 vulnerabilities with CWE-668
CVE-2023-33293 MEDIUM
KaiOS 3.0-3.1 - Unauthenticated Application Enumeration and Manifest Exposure via Local Web Server
CVSS 5.3
CVE-2023-31103 HIGH
Apache InLong <1.6.0 - Privilege Escalation
CVSS 7.5
CVE-2023-31206 HIGH
Apache InLong <1.7.0 - Privilege Escalation
CVSS 7.5
CVE-2023-2025 MEDIUM
OpenBlue Enterprise Manager Data Collector < 3.2.5.75 - Unauthorized Sensitive Information Exposure
CVSS 5.0
CVE-2023-23448 MEDIUM
SICK FTMg AIR FLOW SENSOR - Info Disclosure
CVSS 5.3
CVE-2023-29820 MEDIUM
Webroot SecureAnywhere Endpoint Protection CE <23.1 v.9.0.33.39 - I...
CVSS 5.5
CVE-2023-27564 HIGH
n8n < 0.216.1 - Information Disclosure
CVSS 7.5
CVE-2023-2069 MEDIUM
GitLab 10.0-12.9.7, 12.10-12.10.6, 13.0 - Authenticated CI/CD Variable Exposure via Project Import
CVSS 6.4
CVE-2023-0485 MEDIUM
GitLab 13.11-15.8.4, 15.9-15.9.3, 15.10 - Unauthorized Project Update Access via Fork Diff
CVSS 6.5
CVE-2023-22307 MEDIUM
Tribe29 Checkmk Appliance <1.6.4 - Info Disclosure
CVSS 5.5
CVE-2023-27976 HIGH
EcoStruxure Control Expert >=15.1 - Remote Code Execution via Malicious Web Endpoint Link
CVSS 8.8
CVE-2023-29208 HIGH
XWiki < 13.10.11 - Unauthorized Deleted Document Access
CVSS 7.5
CVE-2023-29203 LOW
XWiki 13.9-13.10.8 - Unauthorized Exposure of Private User Information via uorgsuggest.vm
CVSS 3.7
CVE-2023-25954 MEDIUM
KYOCERA Mobile Print < 3.2.0.230119 - Unauthenticated Arbitrary File Download via Intent Handling
CVSS 5.5
CVE-2023-25409 HIGH
Aten PE8108 2.4.232 - Incorrect Access Control
CVSS 8.1
CVE-2023-26588 HIGH
Buffalo network devices <1.10-0.03 - Info Disclosure
CVSS 7.5
CVE-2023-26458 MEDIUM
SAP Landscape Management <3.0 - Info Disclosure
CVSS 6.8
CVE-2023-29192 LOW
SilverwareGames.io <1.2.19 - Info Disclosure
CVSS 2.7
CVE-2023-1777 MEDIUM
Mattermost < 7.1.6 and 7.8.0 - Unauthorized Message Content Exposure via createPost API
CVSS 6.5
CVE-2023-1775 MEDIUM
Mattermost Server < 7.1.6 - Unauthorized Sensitive Information Exposure via Websocket Event Broadcast
CVSS 4.3
CVE-2023-28336 MEDIUM
Moodle 3.9.0-3.9.19 and 4.1.0-4.1.1 - Exposure of Sensitive Information via Grade Report History
CVSS 4.3
CVE-2023-1402 MEDIUM
Moodle - Information Disclosure via Course Participation Report
CVSS 4.3
CVE-2023-28433 HIGH
Minio <RELEASE.2023-03-20T20-16-18Z - Privilege Escalation
CVSS 8.8
CVE-2023-1562 LOW
Mattermost < 7.5.0 - Exposure of Sensitive Information via Focalboard API
CVSS 3.5
CVE-2023-24906 MEDIUM
Microsoft PostScript and PCL6 Class Printer Driver - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 732