Vulnerabilities > Incorrect Default Permissions

DATE CVE VULNERABILITY TITLE RISK
2022-07-07 CVE-2022-32207 Incorrect Default Permissions vulnerability in multiple products
When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation, it might accidentally *widen* the permissions for the target file, leaving the updated file accessible to more users than intended.
network
low complexity
haxx fedoraproject debian netapp apple splunk CWE-276
critical
9.8
2022-07-07 CVE-2022-33996 Incorrect Default Permissions vulnerability in Devolutions Server
Incorrect permission management in Devolutions Server before 2022.2 allows a new user with a preexisting username to inherit the permissions of that previous user.
network
low complexity
devolutions CWE-276
8.8
2022-07-01 CVE-2022-2270 Incorrect Default Permissions vulnerability in Gitlab
An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1.
network
low complexity
gitlab CWE-276
5.3
2022-06-29 CVE-2022-33023 Incorrect Default Permissions vulnerability in Openhwgroup Cva6
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.
network
low complexity
openhwgroup CWE-276
7.5
2022-06-24 CVE-2021-41635 Incorrect Default Permissions vulnerability in Melag FTP Server 2.2.0.4
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.
network
low complexity
melag CWE-276
8.8
2022-06-24 CVE-2021-41637 Incorrect Default Permissions vulnerability in Melag FTP Server 2.2.0.4
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
local
low complexity
melag CWE-276
7.1
2022-06-21 CVE-2022-1833 Incorrect Default Permissions vulnerability in Redhat AMQ Broker 7.9.4
A flaw was found in AMQ Broker Operator 7.9.4 installed via UI using OperatorHub where a low-privilege user that has access to the namespace where the AMQ Operator is deployed has access to clusterwide edit rights by checking the secrets.
network
low complexity
redhat CWE-276
8.8
2022-06-17 CVE-2022-33912 Incorrect Default Permissions vulnerability in multiple products
A permission issue affects users that deployed the shipped version of the Checkmk Debian package.
local
low complexity
tribe29 checkmk CWE-276
7.8
2022-06-13 CVE-2022-32562 Incorrect Default Permissions vulnerability in Couchbase Server
An issue was discovered in Couchbase Server before 7.0.4.
network
low complexity
couchbase CWE-276
8.8
2022-06-13 CVE-2021-46811 Incorrect Default Permissions vulnerability in Huawei Emui, Harmonyos and Magic UI
HwSEServiceAPP has a vulnerability in permission management.
network
low complexity
huawei CWE-276
5.3