Vulnerabilities > Missing Authorization

DATE CVE VULNERABILITY TITLE RISK
2022-05-30 CVE-2022-1203 Missing Authorization vulnerability in Content Mask Project Content Mask
The Content Mask WordPress plugin before 1.8.4.1 does not have authorisation and CSRF checks in various AJAX actions, as well as does not validate the option to be updated to ensure it belongs to the plugin.
network
low complexity
content-mask-project CWE-862
4.3
2022-05-24 CVE-2020-4926 Missing Authorization vulnerability in IBM Elastic Storage System and Spectrum Scale
A vulnerability in the Spectrum Scale 5.1 core component and IBM Elastic Storage System 6.1 could allow unauthorized access to user data or injection of arbitrary data in the communication protocol.
network
low complexity
ibm CWE-862
critical
9.1
2022-05-20 CVE-2022-28993 Missing Authorization vulnerability in Bdtask Multi Store Inventory Management System 1.0
Multi Store Inventory Management System v1.0 allows attackers to perform an account takeover via a crafted POST request.
network
low complexity
bdtask CWE-862
critical
9.8
2022-05-19 CVE-2022-1423 Missing Authorization vulnerability in Gitlab
Improper access control in the CI/CD cache mechanism in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 allows a malicious actor with Developer privileges to perform cache poisoning leading to arbitrary code execution in protected branches
network
low complexity
gitlab CWE-862
8.8
2022-05-18 CVE-2021-42848 Missing Authorization vulnerability in Lenovo products
An information disclosure vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow an unauthenticated user to retrieve device and networking details.
network
low complexity
lenovo CWE-862
5.3
2022-05-17 CVE-2022-30951 Missing Authorization vulnerability in Jenkins WMI Windows Agents
Jenkins WMI Windows Agents Plugin 1.8 and earlier includes the Windows Remote Command library does not implement access control, potentially allowing users to start processes even if they're not allowed to log in.
network
low complexity
jenkins CWE-862
8.8
2022-05-17 CVE-2022-30954 Missing Authorization vulnerability in Jenkins Blue Ocean
Jenkins Blue Ocean Plugin 1.25.3 and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to connect to an attacker-specified HTTP server.
network
low complexity
jenkins CWE-862
6.5
2022-05-17 CVE-2022-30955 Missing Authorization vulnerability in Jenkins Gitlab
Jenkins GitLab Plugin 1.5.31 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2022-05-17 CVE-2022-30957 Missing Authorization vulnerability in Jenkins SSH
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
4.3
2022-05-17 CVE-2022-30959 Missing Authorization vulnerability in Jenkins SSH
A missing permission check in Jenkins SSH Plugin 2.6.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified SSH server using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5