Vulnerabilities > Incorrect Authorization
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-11-15 | CVE-2022-20928 | Incorrect Authorization vulnerability in Cisco Adaptive Security Appliance Software A vulnerability in the authentication and authorization flows for VPN connections in Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to establish a connection as a different user. This vulnerability is due to a flaw in the authorization verifications during the VPN authentication flow. | 5.8 |
2022-11-15 | CVE-2022-45383 | Incorrect Authorization vulnerability in Jenkins Support Core An incorrect permission check in Jenkins Support Core Plugin 1206.v14049fa_b_d860 and earlier allows attackers with Support/DownloadBundle permission to download a previously created support bundle containing information limited to users with Overall/Administer permission. | 6.5 |
2022-11-15 | CVE-2022-42978 | Incorrect Authorization vulnerability in Atlassian Confluence Data Center In the Netic User Export add-on before 1.3.5 for Atlassian Confluence, authorization is mishandled. | 7.5 |
2022-11-14 | CVE-2022-39385 | Incorrect Authorization vulnerability in Discourse Discourse is the an open source discussion platform. | 6.5 |
2022-11-10 | CVE-2022-39388 | Incorrect Authorization vulnerability in Istio 1.15.0/1.15.1 Istio is an open platform to connect, manage, and secure microservices. | 3.5 |
2022-11-10 | CVE-2022-3819 | Incorrect Authorization vulnerability in Gitlab An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to. | 4.3 |
2022-11-08 | CVE-2022-39352 | Incorrect Authorization vulnerability in Openfga OpenFGA is a high-performance authorization/permission engine inspired by Google Zanzibar. | 9.8 |
2022-11-04 | CVE-2022-20942 | Incorrect Authorization vulnerability in Cisco Asyncos A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA), Cisco Secure Email and Web Manager, and Cisco Secure Web Appliance, formerly known as Cisco Web Security Appliance (WSA), could allow an authenticated, remote attacker to retrieve sensitive information from an affected device, including user credentials. This vulnerability is due to weak enforcement of back-end authorization checks. | 6.5 |
2022-10-25 | CVE-2022-39322 | Incorrect Authorization vulnerability in Keystonejs Keystone 2.2.0/2.3.0 @keystone-6/core is a core package for Keystone 6, a content management system for Node.js. | 9.8 |
2022-10-20 | CVE-2022-42344 | Incorrect Authorization vulnerability in multiple products Adobe Commerce versions 2.4.3-p2 (and earlier), 2.3.7-p3 (and earlier) and 2.4.4 (and earlier) are affected by an Incorrect Authorization vulnerability. | 8.8 |