Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-06-30 CVE-2022-34796 Missing Authorization vulnerability in Jenkins Deployment Dashboard
A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2022-06-30 CVE-2022-34798 Missing Authorization vulnerability in Jenkins Deployment Dashboard
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP URL using attacker-specified credentials.
network
low complexity
jenkins CWE-862
4.3
2022-06-30 CVE-2022-34810 Missing Authorization vulnerability in Jenkins RQM
A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2022-06-30 CVE-2022-34811 Missing Authorization vulnerability in Jenkins Xpath Configuration Viewer
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to access the XPath Configuration Viewer page.
network
low complexity
jenkins CWE-862
4.3
2022-06-30 CVE-2022-34813 Missing Authorization vulnerability in Jenkins Xpath Configuration Viewer
A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/Read permission to create and delete XPath expressions.
network
low complexity
jenkins CWE-862
4.3
2022-06-30 CVE-2022-34818 Missing Authorization vulnerability in Jenkins Failed JOB Deactivator
Jenkins Failed Job Deactivator Plugin 1.2.1 and earlier does not perform permission checks in several views and HTTP endpoints, allowing attackers with Overall/Read permission to disable jobs.
network
low complexity
jenkins CWE-862
4.3
2022-06-27 CVE-2022-0444 Missing Authorization vulnerability in Watchful Xcloner
The Backup, Restore and Migrate WordPress Sites With the XCloner Plugin WordPress plugin before 4.3.6 does not have authorisation and CSRF checks when resetting its settings, allowing unauthenticated attackers to reset them, including generating a new backup encryption key.
network
low complexity
watchful CWE-862
4.3
2022-06-27 CVE-2022-1572 Missing Authorization vulnerability in Html2Wp Project Html2Wp
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks in an AJAX action, available to any authenticated users such as subscriber, which could allow them to delete arbitrary file
network
low complexity
html2wp-project CWE-862
8.1
2022-06-27 CVE-2022-1574 Missing Authorization vulnerability in Html2Wp Project Html2Wp
The HTML2WP WordPress plugin through 1.0.0 does not have authorisation and CSRF checks when importing files, and does not validate them, as a result, unauthenticated attackers can upload arbitrary files (such as PHP) on the remote server
network
low complexity
html2wp-project CWE-862
critical
9.8
2022-06-27 CVE-2022-1903 Missing Authorization vulnerability in Armemberplugin Armember
The ARMember WordPress plugin before 3.4.8 is vulnerable to account takeover (even the administrator) due to missing nonce and authorization checks in an AJAX action available to unauthenticated users, allowing them to change the password of arbitrary users by knowing their username
6.8