Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2021-09-01 CVE-2021-39119 Incorrect Authorization vulnerability in Atlassian Data Center and Jira
Affected versions of Atlassian Jira Server and Data Center allow users who have watched an issue to continue receiving updates on the issue even after their Jira account is revoked, via a Broken Access Control vulnerability in the issue notification feature.
network
low complexity
atlassian CWE-863
5.3
2021-09-01 CVE-2021-36039 Incorrect Authorization vulnerability in Adobe Commerce and Magento Open Source
Magento Commerce versions 2.4.2 (and earlier), 2.4.2-p1 (and earlier) and 2.3.7 (and earlier) are affected by an improper input validation vulnerability via the `quoteId` parameter.
network
low complexity
adobe CWE-863
6.5
2021-08-30 CVE-2021-34434 Incorrect Authorization vulnerability in multiple products
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
network
low complexity
eclipse fedoraproject CWE-863
5.3
2021-08-27 CVE-2021-28696 Incorrect Authorization vulnerability in multiple products
IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered.
low complexity
xen fedoraproject debian CWE-863
6.8
2021-08-25 CVE-2021-22236 Incorrect Authorization vulnerability in Gitlab 14.1.0/14.1.1
Due to improper handling of OAuth client IDs, new subscriptions generated OAuth tokens on an incorrect OAuth client application.
network
low complexity
gitlab CWE-863
8.8
2021-08-25 CVE-2021-22243 Incorrect Authorization vulnerability in Gitlab
Under specialized conditions, GitLab CE/EE versions starting 7.10 may allow existing GitLab users to use an invite URL meant for another email address to gain access into a group.
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22247 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 13.0 allows guests in private projects to view CI/CD analytics
network
low complexity
gitlab CWE-863
4.3
2021-08-25 CVE-2021-22256 Incorrect Authorization vulnerability in Gitlab
Improper authorization in GitLab CE/EE affecting all versions since 12.6 allowed guest users to create issues for Sentry errors and track their status
network
low complexity
gitlab CWE-863
5.4
2021-08-24 CVE-2021-39155 Incorrect Authorization vulnerability in Istio
Istio is an open source platform for providing a uniform way to integrate microservices, manage traffic flow across microservices, enforce policies and aggregate telemetry data.
network
low complexity
istio CWE-863
7.5
2021-08-24 CVE-2021-32777 Incorrect Authorization vulnerability in Envoyproxy Envoy
Envoy is an open source L7 proxy and communication bus designed for large modern service oriented architectures.
network
low complexity
envoyproxy CWE-863
8.3