Vulnerabilities > Incorrect Permission Assignment for Critical Resource
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-05-24 | CVE-2023-31748 | Incorrect Permission Assignment for Critical Resource vulnerability in Wondershare Mobiletrans 4.0.11 Insecure permissions in MobileTrans v4.0.11 allows attackers to escalate privileges to local admin via replacing the executable file. | 7.8 |
2023-05-22 | CVE-2023-31453 | Incorrect Permission Assignment for Critical Resource vulnerability in Apache Inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. | 7.5 |
2023-05-22 | CVE-2023-31454 | Incorrect Permission Assignment for Critical Resource vulnerability in Apache Inlong Incorrect Permission Assignment for Critical Resource Vulnerability in Apache Software Foundation Apache InLong.This issue affects Apache InLong: from 1.2.0 through 1.6.0. The attacker can bind any cluster, even if he is not the cluster owner. | 7.5 |
2023-05-20 | CVE-2023-1692 | Incorrect Permission Assignment for Critical Resource vulnerability in Huawei Emui and Harmonyos The window management module lacks permission verification.Successful exploitation of this vulnerability may affect confidentiality. | 7.5 |
2023-05-16 | CVE-2023-32990 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Azure VM Agents A missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified Azure Cloud server using attacker-specified credentials IDs obtained through another method. | 6.5 |
2023-05-16 | CVE-2023-32992 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Saml Single Sign on Missing permission checks in Jenkins SAML Single Sign On(SSO) Plugin 2.0.2 and earlier allow attackers with Overall/Read permission to send an HTTP request to an attacker-specified URL and parse the response as XML, or parse a local file on the Jenkins controller as XML. | 8.8 |
2023-05-16 | CVE-2023-33004 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins TAG Profiler A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics. | 4.3 |
2023-05-16 | CVE-2023-32979 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins Email Extension Jenkins Email Extension Plugin does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of files in the email-templates/ directory in the Jenkins home directory on the controller file system. | 4.3 |
2023-05-16 | CVE-2023-32986 | Incorrect Permission Assignment for Critical Resource vulnerability in Jenkins File Parameters Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content. | 8.8 |
2023-05-12 | CVE-2023-32303 | Incorrect Permission Assignment for Critical Resource vulnerability in Planet Planet is software that provides satellite data. | 5.5 |