Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-10-19 CVE-2022-43427 Missing Authorization vulnerability in Jenkins Compuware Topaz for Total Test
Jenkins Compuware Topaz for Total Test Plugin 2.4.8 and earlier does not perform permission checks in several HTTP endpoints, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2022-10-19 CVE-2022-43431 Missing Authorization vulnerability in Jenkins Compuware Strobe Measurement
Jenkins Compuware Strobe Measurement Plugin 1.0.1 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2022-10-19 CVE-2022-39233 Missing Authorization vulnerability in Enalean Tuleap
Tuleap is a Free & Open Source Suite to improve management of software developments and collaboration.
network
low complexity
enalean CWE-862
5.4
2022-10-17 CVE-2022-3082 Missing Authorization vulnerability in Miniorange Discord Integration
The miniOrange Discord Integration WordPress plugin before 2.1.6 does not have authorisation and CSRF in some of its AJAX actions, allowing any logged in users, such as subscriber to call them, and disable the app for example
network
low complexity
miniorange CWE-862
6.5
2022-10-17 CVE-2022-3501 Missing Authorization vulnerability in Otrs
Article template contents with sensitive data could be accessed from agents without permissions.
network
low complexity
otrs CWE-862
7.5
2022-10-14 CVE-2022-2985 Missing Authorization vulnerability in Google Android 10.0/11.0
In music service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38669 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In soundrecorder service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38670 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In soundrecorder service, there is a missing permission check.
local
low complexity
google CWE-862
7.8
2022-10-14 CVE-2022-38677 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In cell service, there is a missing permission check.
local
low complexity
google CWE-862
5.5
2022-10-14 CVE-2022-38679 Missing Authorization vulnerability in Google Android 10.0/11.0/12.0
In music service, there is a missing permission check.
local
low complexity
google CWE-862
5.5