Vulnerabilities > Authorization Bypass Through User-Controlled Key
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-12-14 | CVE-2021-43820 | Authorization Bypass Through User-Controlled Key vulnerability in Seafile Server Seafile is an open source cloud storage system. | 5.9 |
2021-12-14 | CVE-2021-44949 | Authorization Bypass Through User-Controlled Key vulnerability in Glfusion 1.7.9 glFusion CMS 1.7.9 is affected by an access control vulnerability via /public_html/users.php. | 9.8 |
2021-12-13 | CVE-2021-39916 | Authorization Bypass Through User-Controlled Key vulnerability in Gitlab Lack of an access control check in the External Status Check feature allowed any authenticated user to retrieve the configuration of any External Status Check in GitLab EE starting from 14.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. | 4.3 |
2021-12-13 | CVE-2021-39934 | Authorization Bypass Through User-Controlled Key vulnerability in Gitlab Improper access control allows any project member to retrieve the service desk email address in GitLab CE/EE versions starting 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. | 4.3 |
2021-12-01 | CVE-2021-3964 | Authorization Bypass Through User-Controlled Key vulnerability in Elgg elgg is vulnerable to Authorization Bypass Through User-Controlled Key | 5.9 |
2021-12-01 | CVE-2021-3992 | Authorization Bypass Through User-Controlled Key vulnerability in Kimai2 Project Kimai2 kimai2 is vulnerable to Improper Access Control | 6.5 |
2021-11-30 | CVE-2021-36329 | Authorization Bypass Through User-Controlled Key vulnerability in Dell EMC Streaming Data Platform Dell EMC Streaming Data Platform versions before 1.3 contain an Indirect Object Reference Vulnerability. | 6.5 |
2021-11-23 | CVE-2021-24892 | Authorization Bypass Through User-Controlled Key vulnerability in Advanced Forms Project Advanced Forms Insecure Direct Object Reference in edit function of Advanced Forms (Free & Pro) before 1.6.9 allows authenticated remote attacker to change arbitrary user's email address and request for reset password, which could lead to take over of WordPress's administrator account. | 8.8 |
2021-11-19 | CVE-2021-22951 | Authorization Bypass Through User-Controlled Key vulnerability in Concretecms Concrete CMS Unauthorized individuals could view password protected files using view_inline in Concrete CMS (previously concrete 5) prior to version 8.5.7. | 7.5 |
2021-11-19 | CVE-2021-22967 | Authorization Bypass Through User-Controlled Key vulnerability in Concretecms Concrete CMS In Concrete CMS (formerly concrete 5) below 8.5.7, IDOR Allows Unauthenticated User to Access Restricted Files If Allowed to Add Message to a Conversation.To remediate this, a check was added to verify a user has permissions to view files before attaching the files to a message in "add / edit message”.Concrete CMS security team gave this a CVSS v3.1 score of 4.3 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NCredit for discovery Adrian H | 7.5 |