Vulnerabilities > Incorrect Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-03-10 | CVE-2023-27899 | Incorrect Authorization vulnerability in Jenkins Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a plugin for installation, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used, potentially resulting in arbitrary code execution. | 7.0 |
2023-03-10 | CVE-2023-27903 | Incorrect Authorization vulnerability in Jenkins Jenkins 2.393 and earlier, LTS 2.375.3 and earlier creates a temporary file in the default temporary directory with the default permissions for newly created files when uploading a file parameter through the CLI, potentially allowing attackers with access to the Jenkins controller file system to read and write the file before it is used. | 4.4 |
2023-03-08 | CVE-2022-4315 | Incorrect Authorization vulnerability in Gitlab Dynamic Application Security Testing Analyzer An issue has been discovered in GitLab DAST analyzer affecting all versions starting from 2.0 before 3.0.55, which sends custom request headers with every request on the authentication page. | 6.5 |
2023-03-08 | CVE-2023-22891 | Incorrect Authorization vulnerability in Smartbear Zephyr Enterprise There exists a privilege escalation vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by authorized users to reset passwords for other accounts. | 8.1 |
2023-03-03 | CVE-2023-1164 | Incorrect Authorization vulnerability in Kylinos Kylin OS A vulnerability was found in KylinSoft kylin-activation on KylinOS and classified as critical. | 7.8 |
2023-03-02 | CVE-2023-26056 | Incorrect Authorization vulnerability in Xwiki XWiki Platform is a generic wiki platform. | 5.4 |
2023-03-01 | CVE-2023-0952 | Incorrect Authorization vulnerability in Devolutions Server Improper access controls on entries in Devolutions Server 2022.3.12 and earlier could allow an authenticated user to access sensitive data without proper authorization. | 6.5 |
2023-02-28 | CVE-2023-25575 | Incorrect Authorization vulnerability in Api-Platform Core API Platform Core is the server component of API Platform: hypermedia and GraphQL APIs. | 6.5 |
2023-02-23 | CVE-2023-23918 | Incorrect Authorization vulnerability in Nodejs Node.Js A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). | 7.5 |
2023-02-17 | CVE-2023-23064 | Incorrect Authorization vulnerability in Totolink A720R Firmware 4.1.5Cu.532B20210610 TOTOLINK A720R V4.1.5cu.532_ B20210610 is vulnerable to Incorrect Access Control. | 9.8 |