Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-12-13 CVE-2021-39918 Incorrect Authorization vulnerability in Gitlab
Incorrect Authorization in GitLab EE affecting all versions starting from 11.1 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows a user to add comments to a vulnerability which cannot be accessed.
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39930 Incorrect Authorization vulnerability in Gitlab
Missing authorization in GitLab EE versions between 12.4 and 14.3.6, between 14.4.0 and 14.4.4, and between 14.5.0 and 14.5.2 allowed an attacker to access a user's custom project and group templates
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39936 Incorrect Authorization vulnerability in Gitlab
Improper access control in GitLab CE/EE affecting all versions starting from 10.7 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an attacker in possession of a deploy token to access a project's disabled wiki.
network
low complexity
gitlab CWE-863
4.3
2021-12-13 CVE-2021-39945 Incorrect Authorization vulnerability in Gitlab
Improper access control in the GitLab CE/EE API affecting all versions starting from 9.4 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, allows an author of a Merge Request to approve the Merge Request even after having their project access revoked
network
low complexity
gitlab CWE-863
2.7
2021-12-13 CVE-2021-24819 Incorrect Authorization vulnerability in Page/Post Content Shortcode Project Page/Post Content Shortcode 1.0
The Page/Post Content Shortcode WordPress plugin through 1.0 does not have proper authorisation in place, allowing users with a role as low as contributor to access draft/private/password protected/trashed posts/pages they should not be allowed to, including posts created by other users such as admins and editors.
4.3
2021-12-12 CVE-2021-41805 Incorrect Authorization vulnerability in Hashicorp Consul
HashiCorp Consul Enterprise before 1.8.17, 1.9.x before 1.9.11, and 1.10.x before 1.10.4 has Incorrect Access Control.
network
low complexity
hashicorp CWE-863
8.8
2021-12-09 CVE-2021-29678 Incorrect Authorization vulnerability in multiple products
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 9.7, 10.1, 10.5, 11.1, and 11.5 could allow a user with DBADM authority to access other databases and read or modify files.
network
low complexity
ibm netapp CWE-863
8.7
2021-12-08 CVE-2021-38503 Incorrect Authorization vulnerability in multiple products
The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame.
network
low complexity
mozilla debian CWE-863
critical
10.0
2021-12-08 CVE-2021-41013 Incorrect Authorization vulnerability in Fortinet Fortiweb
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may allow an unauthorized and unauthenticated user to access the Log reports via their URLs.
network
low complexity
fortinet CWE-863
5.3
2021-12-08 CVE-2021-42758 Incorrect Authorization vulnerability in Fortinet Fortiwlc
An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to execute any command as an admin user with full access rights via bypassing the GUI restrictions.
network
low complexity
fortinet CWE-863
8.8