CWE-863

High likelihood

Incorrect Authorization

Parent: CWE-285 - Improper Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

3,104 vulnerabilities with CWE-863
CVE-2021-40639 HIGH
Jfinal CMS 5.1.0 - Incorrect Authorization via /classes/conf/db.properties
CVSS 7.5
CVE-2021-39206 HIGH
Envoy < 1.16.5 - Incorrect Authorization
CVSS 8.6
CVE-2021-28911 CRITICAL
BAB TECHNOLOGIE eibPort V3 < 3.9.1 - Unauthenticated Sensitive Data Exposure in /tmp Path
CVSS 9.8
CVE-2021-22239 MEDIUM
GitLab 14.0.0-14.0.7 - Unauthenticated Metadata Injection in Issue Creation
CVSS 5.0
CVE-2021-28567 MEDIUM
Magento < 2.4.2 - Authenticated Improper Authorization in Customers Module
CVSS 6.5
CVE-2021-35526 MEDIUM
Hitachi ABB Power Grids System Data Manager - Info Disclosure
CVSS 6.3
CVE-2021-1854 MEDIUM
iPadOS < 14.5 - Unauthenticated Call Termination Bypass
CVSS 4.3
CVE-2021-35949 MEDIUM
ownCloud Server <10.8.0 - Auth Bypass
CVSS 5.3
CVE-2021-38312 HIGH
Gutenberg Template Library & Redux Framework <= 4.2.11 - Auth Bypass
CVSS 7.1
CVE-2021-39119 MEDIUM
Atlassian Jira Server and Data Center < 8.19.0 - Broken Access Control in Issue Notification Feature
CVSS 5.3
CVE-2021-36039 MEDIUM
Magento Commerce <2.4.2-2.3.7 - Info Disclosure
CVSS 6.5
CVE-2021-39164 LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Room Membership via History Visibility
CVSS 3.1
CVE-2021-39163 LOW
Matrix Synapse < 1.41.1 - Unauthenticated Exposure of Sensitive Room Information via Group Endpoints
CVSS 3.1
CVE-2021-34434 MEDIUM
Eclipse Mosquitto 2.0-2.0.11 - Improper Authorization in Dynamic Security Plugin
CVSS 5.3
CVE-2021-28696 MEDIUM
Xen - Incorrect Authorization in IOMMU Page Mapping
CVSS 6.8
CVE-2021-22256 MEDIUM
GitLab 12.6.0-13.12.8 - Unauthenticated Issue Creation for Sentry Errors
CVSS 5.4
CVE-2021-22247 MEDIUM
GitLab 13.0.0-13.12.9 - Incorrect Authorization for CI/CD Analytics
CVSS 4.3
CVE-2021-22243 MEDIUM
GitLab 7.10.0-13.12.8 - Incorrect Authorization via Invite URL
CVSS 5.0
CVE-2021-22236 MEDIUM
GitLab 14.1.0-14.1.1 - Incorrect Authorization via OAuth Client ID Handling
CVSS 5.5
CVE-2021-39156 HIGH
Istio < 1.9.8 - Authorization Bypass via URI Fragment
CVSS 8.1
CVE-2021-39155 HIGH
Istio < 1.9.8 - Authorization Policy Bypass via Case-Sensitive Hostname Comparison
CVSS 8.3
CVE-2021-32779 HIGH
Envoy 1.16.0-1.16.4 - Privilege Escalation via URI Fragment Mishandling
CVSS 8.6
CVE-2021-32777 HIGH
Envoy 1.16.0-1.16.4 - Authorization Bypass via Ext-Authz Header Merging
CVSS 8.6
CVE-2021-30987 MEDIUM
macOS Monterey <12.1 - Info Disclosure
CVSS 5.5
CVE-2021-30975 HIGH
macOS < 10.15.7 and 11.0-11.6.2 - Gatekeeper Bypass via Malicious OSAX Scripting Addition
CVSS 8.6
Details
Vulnerabilities 3,104
Exploit Likelihood High