Vulnerabilities > Incorrect Authorization

DATE CVE VULNERABILITY TITLE RISK
2020-11-23 CVE-2020-28053 Incorrect Authorization vulnerability in Hashicorp Consul
HashiCorp Consul and Consul Enterprise 1.2.0 up to 1.8.5 allowed operators with operator:read ACL permissions to read the Connect CA private key configuration.
network
low complexity
hashicorp CWE-863
6.5
2020-11-19 CVE-2020-25701 Incorrect Authorization vulnerability in multiple products
If the upload course tool in Moodle was used to delete an enrollment method which did not exist or was not already enabled, the tool would erroneously enable that enrollment method.
network
low complexity
moodle fedoraproject CWE-863
5.3
2020-11-19 CVE-2020-25699 Incorrect Authorization vulnerability in multiple products
In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course.
network
low complexity
moodle fedoraproject CWE-863
7.5
2020-11-19 CVE-2020-8278 Incorrect Authorization vulnerability in Nextcloud Social 0.3.1
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
network
low complexity
nextcloud CWE-863
5.3
2020-11-12 CVE-2020-11209 Incorrect Authorization vulnerability in Qualcomm products
Improper authorization in DSP process could allow unauthorized users to downgrade the library versions in SD820, SD821, SD820, QCS603, QCS605, SDA855, SA6155P, SA6145P, SA6155, SA6155P, SD855, SD 675, SD660, SD429, SD439
local
low complexity
qualcomm CWE-863
5.5
2020-11-09 CVE-2020-25655 Incorrect Authorization vulnerability in Redhat Advanced Cluster Management for Kubernetes 2.0
An issue was discovered in ManagedClusterView API, that could allow secrets to be disclosed to users without the correct permissions.
network
low complexity
redhat CWE-863
6.5
2020-11-06 CVE-2020-3600 Incorrect Authorization vulnerability in Cisco Sd-Wan
A vulnerability in Cisco SD-WAN Software could allow an authenticated, local attacker to elevate privileges to root on the underlying operating system.
local
low complexity
cisco CWE-863
7.8
2020-11-06 CVE-2020-3592 Incorrect Authorization vulnerability in Cisco Catalyst Sd-Wan Manager and Sd-Wan Vmanage
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an authenticated, remote attacker to bypass authorization and modify the configuration of an affected system.
network
low complexity
cisco CWE-863
6.5
2020-11-05 CVE-2020-26506 Incorrect Authorization vulnerability in Marmind 4.1.141.0
An Authorization Bypass vulnerability in the Marmind web application with version 4.1.141.0 allows users with lower privileges to gain control to files uploaded by administrative users.
network
low complexity
marmind CWE-863
4.3
2020-10-27 CVE-2020-3852 Incorrect Authorization vulnerability in Apple Safari
A logic issue was addressed with improved validation.
network
low complexity
apple CWE-863
5.3