Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2023-01-13 CVE-2023-0091 Incorrect Authorization vulnerability in Redhat Keycloak
A flaw was found in Keycloak, where it did not properly check client tokens for possible revocation in its client credential flow.
network
low complexity
redhat CWE-863
3.8
2023-01-12 CVE-2022-4167 Incorrect Authorization vulnerability in Gitlab
Incorrect Authorization check affecting all versions of GitLab EE from 13.11 prior to 15.5.7, 15.6 prior to 15.6.4, and 15.7 prior to 15.7.2 allows group access tokens to continue working even after the group owner loses the ability to revoke them.
network
low complexity
gitlab CWE-863
7.5
2023-01-11 CVE-2023-22945 Incorrect Authorization vulnerability in multiple products
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
network
low complexity
mediawiki fedoraproject CWE-863
4.3
2023-01-09 CVE-2015-10033 Incorrect Authorization vulnerability in Merlinsboard Project Merlinsboard
A vulnerability, which was classified as problematic, was found in jvvlee MerlinsBoard.
network
low complexity
merlinsboard-project CWE-863
6.5
2023-01-09 CVE-2022-46258 Incorrect Authorization vulnerability in Github Enterprise Server
An incorrect authorization vulnerability was identified in GitHub Enterprise Server that allowed a repository-scoped token with read/write access to modify Action Workflow files without a Workflow scope.
network
low complexity
github CWE-863
6.5
2022-12-26 CVE-2021-45466 Incorrect Authorization vulnerability in Control-Webpanel Webpanel
In CWP (aka Control Web Panel or CentOS Web Panel) before 0.9.8.1107, attackers can make a crafted request to api/?api=add_server&DHCP= to add an authorized_keys text file in the /resources/ folder.
network
low complexity
control-webpanel CWE-863
critical
9.8
2022-12-25 CVE-2022-45891 Incorrect Authorization vulnerability in Planetestream Planet Estream
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
network
low complexity
planetestream CWE-863
critical
9.1
2022-12-22 CVE-2022-22754 Incorrect Authorization vulnerability in Mozilla Firefox
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions.
network
low complexity
mozilla CWE-863
6.5
2022-12-22 CVE-2022-38475 Incorrect Authorization vulnerability in Mozilla Firefox
An attacker could have written a value to the first element in a zero-length JavaScript array.
network
low complexity
mozilla CWE-863
6.5
2022-12-20 CVE-2022-43872 Incorrect Authorization vulnerability in IBM Financial Transaction Manager 3.2.4
IBM Financial Transaction Manager 3.2.4 authorization checks are done incorrectly for some HTTP requests which allows getting unauthorized technical information (e.g.
network
low complexity
ibm CWE-863
5.3