CWE-668

Exposure of Resource to Wrong Sphere

Parent: CWE-664 - Improper Control of a Resource Through its Lifetime

The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.

719 vulnerabilities with CWE-668
CVE-2022-41954 LOW
mpxj < 10.14.1 - Insecure Temporary File Permissions on Unix-like Systems
CVSS 3.3
CVE-2022-38813 HIGH
PHPGurukul Blood Donor Mgmt <1.0 - Info Disclosure
CVSS 8.1
CVE-2022-41946 MEDIUM
PostgreSQL JDBC Driver 42.2.0-42.2.27 - Insecure Temporary File Creation via InputStream Handling
CVSS 4.7
CVE-2022-3952 LOW
ManyDesigns Portofino < 5.3.3 - Insecure Temporary File Permissions in WarFileLauncher.java
CVSS 2.6
CVE-2022-41874 LOW
Tauri <1.0.7-1.1.2 - Info Disclosure
CVSS 2.6
CVE-2022-3866 MEDIUM
HashiCorp Nomad <1.4.2 - Info Disclosure
CVSS 5.0
CVE-2022-2882 MEDIUM
GitLab CE/EE <15.2.5, <15.3.4, <15.4.1 - Info Disclosure
CVSS 5.5
CVE-2022-39349 MEDIUM
Tasks.org < 12.7.1 - Unintended Proxy via ShareLinkActivity File Path Handling
CVSS 5.5
CVE-2022-39309 MEDIUM
GoCD < 21.1.0 - Authenticated Sensitive Data Exposure via Symmetric Key Leak
CVSS 4.9
CVE-2022-39015 MEDIUM
BOE AdminTools/BOE SDK - Info Disclosure
CVSS 6.5
CVE-2022-26121 LOW
FortiAnalyzer FortiManager GUI <7.0.4 - Info Disclosure
CVSS 3.7
CVE-2022-39871 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control in cloudNotificationManager.java
CVSS 4.0
CVE-2022-39870 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control via PUSH_MESSAGE_RECEIVED Broadcast
CVSS 4.0
CVE-2022-39869 MEDIUM
Samsung SmartThings < 1.7.89.0 - Improper Access Control via REMOVE_PERSISTENT_BANNER Broadcast
CVSS 4.0
CVE-2022-23950 HIGH
Keylime <6.3.0 - Privilege Escalation
CVSS 7.5
CVE-2022-40234 MEDIUM
IBM Spectrum Protect Plus < 10.1.12 - Private Key Exposure in TLS Certificate Upload
CVSS 5.9
CVE-2022-34867 HIGH
WP Libre Form 2 2.0.0-2.0.8 - Unauthenticated Sensitive Information Disclosure
CVSS 7.3
CVE-2022-2403 MEDIUM
OpenShift >=4.9 - Authenticated Credentials Leak via oauth-serving-cert ConfigMap
CVSS 6.5
CVE-2022-1902 HIGH
Red Hat Advanced Cluster Security - Privilege Escalation
CVSS 8.8
CVE-2022-0852 MEDIUM
convert2rhel < 0.26 - Unauthorized Password Exposure via Command Line
CVSS 5.5
CVE-2022-29850 HIGH
Lexmark Multiple Models Firmware Persistence Across Reboots via Compromised Device
CVSS 8.1
CVE-2022-2610 MEDIUM
Google Chrome <104.0.5112.79 - Info Disclosure
CVSS 6.5
CVE-2022-35936 HIGH
Ethermint <0.17.2 - Info Disclosure
CVSS 8.2
CVE-2022-1875 MEDIUM
Google Chrome <102.0.5005.61 - Info Disclosure
CVSS 4.3
CVE-2022-1873 MEDIUM
Google Chrome <102.0.5005.61 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 719