Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-09-07 CVE-2020-19765 Incorrect Authorization vulnerability in Proofofdiligencetoken Project Proofofdiligencetoken 1.0
An issue in the noReentrance() modifier of the Ethereum-based contract Accounting 1.0 allows attackers to carry out a reentrancy attack.
network
low complexity
proofofdiligencetoken-project CWE-863
7.5
2021-09-07 CVE-2021-35949 Incorrect Authorization vulnerability in Owncloud
The shareinfo controller in the ownCloud Server before 10.8.0 allows an attacker to bypass the permission checks for upload only shares and list metadata about the share.
network
low complexity
owncloud CWE-863
5.3
2021-09-02 CVE-2021-38312 Incorrect Authorization vulnerability in Redux Gutenberg Template Library & Redux Framework
The Gutenberg Template Library & Redux Framework plugin <= 4.2.11 for WordPress used an incorrect authorization check in the REST API endpoints registered under the “redux/v1/templates/” REST Route in “redux-templates/classes/class-api.php”.
network
low complexity
redux CWE-863
6.5
2021-09-01 CVE-2021-39119 Incorrect Authorization vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature.
network
low complexity
atlassian CWE-863
5.3
2021-08-30 CVE-2021-34434 Incorrect Authorization vulnerability in multiple products
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
network
low complexity
eclipse fedoraproject CWE-863
5.3
2021-08-27 CVE-2021-28696 Incorrect Authorization vulnerability in multiple products
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered.
low complexity
xen fedoraproject debian CWE-863
6.8
2021-08-25 CVE-2021-22236 Incorrect Authorization vulnerability in Gitlab 14.1.0/14.1.1
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application.
network
low complexity
gitlab CWE-863
8.8
2021-08-25 CVE-2021-22243 Incorrect Authorization vulnerability in Gitlab
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22247 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22256 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
network
low complexity
gitlab CWE-863
5.4