Show filters
977 Total Results
Displaying 431-440 of 977
Sort by:
Attacker Value
Unknown

CVE-2023-25817

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has been addressed andit is recommended that the Nextcloud Server is upgraded to 24.0.9. There are no known workarounds for this vulnerability.
Attacker Value
Unknown

CVE-2023-1135

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
In Delta Electronics InfraSuite Device Master versions prior to 1.0.5, an attacker could set incorrect directory permissions, which could result in local privilege escalation.
Attacker Value
Unknown

CVE-2023-27096

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker to obtain sensitive information via the ConfigVerifyController function of the Tenant Management module.
Attacker Value
Unknown

CVE-2022-3146

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file. This issue leads to information disclosure of important configuration details from the OpenStack deployment.
Attacker Value
Unknown

CVE-2022-3101

Disclosure Date: March 23, 2023 (last updated February 24, 2025)
A flaw was found in tripleo-ansible. Due to an insecure default configuration, the permissions of a sensitive file are not sufficiently restricted. This flaw allows a local attacker to use brute force to explore the relevant directory and discover the file, leading to information disclosure of important configuration details from the OpenStack deployment.
Attacker Value
Unknown

CVE-2023-27095

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
Insecure Permissions vulnerability found in OpenGoofy Hippo4j v.1.4.3 allows attacker toescalate privileges via the AddUser method of the UserController function in Tenant Management module.
Attacker Value
Unknown

CVE-2023-27084

Disclosure Date: March 16, 2023 (last updated February 24, 2025)
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter.
Attacker Value
Unknown

CVE-2023-23939

Disclosure Date: March 06, 2023 (last updated February 24, 2025)
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer runs `fs.chmodSync(kubectlPath, 777)` to set permissions on the Kubectl binary, however, this allows any local user to replace the Kubectl binary. This allows privilege escalation to the user that can also run kubectl, most likely root. This attack is only possible if an attacker somehow breached the GitHub actions runner or if a user is utilizing an Action that maliciously executes this attack. This has been fixed and released in all versions `v3` and later. 775 permissions are used instead. Users are advised to upgrade. There are no known workarounds for this issue.
Attacker Value
Unknown

CVE-2023-1105

Disclosure Date: March 01, 2023 (last updated February 24, 2025)
External Control of File Name or Path in GitHub repository flatpressblog/flatpress prior to 1.3.
Attacker Value
Unknown

CVE-2023-1070

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
External Control of File Name or Path in GitHub repository nilsteampassnet/teampass prior to 3.0.0.22.