Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-08-25 CVE-2021-22243 Incorrect Authorization vulnerability in Gitlab
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22247 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22256 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
network
low complexity
gitlab CWE-863
5.4
2021-08-24 CVE-2021-39155 Incorrect Authorization vulnerability in Istio
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data.
network
low complexity
istio CWE-863
7.5
2021-08-24 CVE-2021-32777 Incorrect Authorization vulnerability in Envoyproxy Envoy
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures.
network
low complexity
envoyproxy CWE-863
8.3
2021-08-24 CVE-2021-30856 Incorrect Authorization vulnerability in Apple Macos
This issue was addressed by adding a new Remote Login option for opting into Full Disk Access for Secure Shell sessions.
network
low complexity
apple CWE-863
critical
9.1
2021-08-24 CVE-2021-30925 Incorrect Authorization vulnerability in Apple products
The issue was addressed with improved permissions logic.
network
low complexity
apple CWE-863
critical
9.1
2021-08-24 CVE-2021-30972 Incorrect Authorization vulnerability in Apple mac OS X and Macos
This issue was addressed with improved checks.
local
low complexity
apple CWE-863
5.5
2021-08-24 CVE-2021-30975 Incorrect Authorization vulnerability in Apple mac OS X and Macos
This issue was addressed by disabling execution of JavaScript when viewing a scripting dictionary.
local
low complexity
apple CWE-863
8.6
2021-08-24 CVE-2021-30987 Incorrect Authorization vulnerability in Apple Macos 12.0/12.0.0/12.0.1
An access issue was addressed with improved access restrictions.
local
low complexity
apple CWE-863
5.5