Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-03-20 CVE-2023-27578 Incorrect Authorization vulnerability in Galaxyproject Galaxy
Galaxy is an open-source platform for data analysis.
network
low complexity
galaxyproject CWE-863
7.5
2023-03-20 CVE-2023-0940 Incorrect Authorization vulnerability in Metagauss Profilegrid
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization.
network
low complexity
metagauss CWE-863
8.8
2023-03-17 CVE-2023-27594 Incorrect Authorization vulnerability in Cilium
Cilium is a networking, observability, and security solution with an eBPF-based dataplane.
network
low complexity
cilium CWE-863
7.3
2023-03-11 CVE-2023-24999 Incorrect Authorization vulnerability in Hashicorp Vault
HashiCorp Vault and Vault Enterprise’s approle auth method allowed any authenticated user with access to an approle destroy endpoint to destroy the secret ID of any other role by providing the secret ID accessor.
network
low complexity
hashicorp CWE-863
8.1
2023-03-10 CVE-2023-27899 Incorrect Authorization vulnerability in Jenkins
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution.
local
high complexity
jenkins CWE-863
7.0
2023-03-10 CVE-2023-27903 Incorrect Authorization vulnerability in Jenkins
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used.
local
low complexity
jenkins CWE-863
4.4
2023-03-08 CVE-2022-4315 Incorrect Authorization vulnerability in Gitlab Dynamic Application Security Testing Analyzer
An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page.
network
low complexity
gitlab CWE-863
6.5
2023-03-08 CVE-2023-22891 Incorrect Authorization vulnerability in Smartbear Zephyr Enterprise
There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts.
network
low complexity
smartbear CWE-863
8.1
2023-03-03 CVE-2023-1164 Incorrect Authorization vulnerability in Kylinos Kylin OS
A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical.
local
low complexity
kylinos CWE-863
7.8
2023-03-02 CVE-2023-26056 Incorrect Authorization vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-863
5.4