5581 vulnerabilities classified as CWE-862 (授权机制缺失). AI Chinese analysis included.
CWE-862 represents a critical access control weakness where software fails to verify an actor’s permissions before granting access to resources or executing actions. Attackers typically exploit this flaw by manipulating requests to access sensitive data or perform privileged operations that should be restricted to authorized users. Without proper checks, malicious actors can bypass authentication mechanisms entirely, leading to unauthorized data exposure, modification, or system compromise. Developers mitigate this risk by implementing robust authorization logic at every entry point, ensuring that identity verification is coupled with strict permission validation. This involves checking user roles and access rights against the requested resource before processing any request. By integrating these checks into the application’s core architecture and utilizing established frameworks, teams can prevent unauthorized access and maintain the integrity of their systems against exploitation.
function runEmployeeQuery($dbName, $name){ mysql_select_db($dbName,$globalDbHandle) or die("Could not open Database".$dbName); //Use a prepared statement to avoid CWE-89 $preparedStatement = $globalDbHandle->prepare('SELECT * FROM employees WHERE name = :name'); $preparedStatement->execute(array(':name' => $name)); return $preparedStatement->fetchAll(); } /.../ $employeeRecord = runEmployeeQuery('EmployeeDB',$_GET['EmployeeName']);sub DisplayPrivateMessage { my($id) = @_; my $Message = LookupMessageObject($id); print "From: " . encodeHTML($Message->{from}) . "<br>\n"; print "Subject: " . encodeHTML($Message->{subject}) . "\n"; print "<hr>\n"; print "Body: " . encodeHTML($Message->{body}) . "\n"; } my $q = new CGI; # For purposes of this example, assume that CWE-309 and # CWE-523 do not apply. if (! AuthenticateUser($q->param('username'), $q->param('password'))) { ExitError("invalid username or password"); } my $id = $q->param('id'); DisplayPrivateMessage($id);| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-0715 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_clone_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-08 |
| CVE-2023-0711 | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_save_state — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-08 |
| CVE-2023-0717 | Wicked Folders <= 2.18.16 - Missing Authorization via ajax_delete_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-08 |
| CVE-2023-0720 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder_order — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-08 |
| CVE-2023-0716 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_edit_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-08 |
| CVE-2023-0718 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-07 |
| CVE-2023-0712 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_move_object — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-07 |
| CVE-2023-0719 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_save_sort_order — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-07 |
| CVE-2023-0713 | Wicked Folders <= 2.18.16 - Missing Authorization on ajax_add_folder — Wicked Folders – Folder Organizer for Pages, Posts, and Custom Post Types | 5.4 | Medium | 2023-02-07 |
| CVE-2022-21953 | Authenticated user can gain unauthorized shell pod and kubectl access in the local cluster — Rancher | 7.4 | High | 2023-02-07 |
| CVE-2023-0678 | Missing Authorization in phpipam/phpipam — phpipam/phpipam | 4.3 | - | 2023-02-04 |
| CVE-2023-0619 | Kraken.io Image Optimizer <= 2.6.8 - Missing Authorization to Authenticated (Subscriber+) Plugin Options Update — Kraken.io Image Optimizer | 6.5 | Medium | 2023-02-01 |
| CVE-2023-22737 | wire-server vulnerable to unauthorized removal of Bots from Conversations — wire-server | 6.5 | Medium | 2023-01-27 |
| CVE-2023-0556 | ContentStudio <= 1.2.5 - Missing Authorization — ContentStudio | 9.8 | Critical | 2023-01-27 |
| CVE-2023-0555 | Quick Restaurant Menu <= 2.0.2 - Missing Authorization — Quick Restaurant Menu | 8.1 | High | 2023-01-27 |
| CVE-2023-22736 | argo-cd Controller reconciles apps outside configured namespaces when sharding is enabled — argo-cd | 8.6 | High | 2023-01-26 |
| CVE-2023-23611 | xblock-lti-consumer contain Missing Authorization in Grade Pass Back Implementation — xblock-lti-consumer | 5.4 | Medium | 2023-01-25 |
| CVE-2023-0447 | My YouTube Channel <= 3.0.12.1 - Missing Authorization — My YouTube Channel | 4.3 | Medium | 2023-01-23 |
| CVE-2023-0404 | Events Made Easy <= 2.3.16 - Missing Authorization — Events Made Easy | 5.4 | Medium | 2023-01-19 |
| CVE-2023-0402 | Social Warfare <= 4.3.0 - Missing Authorization — Social Sharing Plugin – Social Warfare | 5.4 | Medium | 2023-01-19 |
| CVE-2018-14628 | Samba 安全漏洞 — Samba | 4.3 | - | 2023-01-17 |
| CVE-2023-22478 | KubePi is vulnerable to missing authorization — KubePi | 7.3 | High | 2023-01-14 |
| CVE-2023-0293 | Mediamatic – Media Library Folders <= 2.8.1 - Missing Authorization — Mediamatic – Media Library Folders | 4.3 | Medium | 2023-01-13 |
| CVE-2023-22489 | Flarum is missing authorization in discussion replies — framework | 3.5 | Low | 2023-01-13 |
| CVE-2023-22488 | Missing authorization in Flarum — framework | 6.8 | Medium | 2023-01-12 |
| CVE-2022-38678 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-38682 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-38683 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-38684 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
| CVE-2022-39104 | UNISOC chipset 安全漏洞 — SC9863A/SC9832E/SC7731E/T610/T310/T606/T760/T610/T618/T606/T612/T616/T760/T770/T820/S8000 | 5.5 | - | 2023-01-04 |
Vulnerabilities classified as CWE-862 (授权机制缺失) represent 5581 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.