Bypass Security

Apiman security bypass | CVE-2023-28640

NAME__________Apiman security bypassPlatforms Affected:Risk Level:6.4Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Apiman could allow a remote authenticated attacker to bypass security restrictions, caused by improper handling of insufficient permissions. By sending a specially-crafted request, an…

lambdaisland/uri security bypass | CVE-2023-28628

NAME__________lambdaisland/uri security bypassPlatforms Affected:lambdaisland/uri lambdaisland/uri 1.13.95Risk Level:5.4Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________lambdaisland/uri could allow a remote attacker to bypass security restrictions, caused by a flaw with authority-regex function returns the wrong authority. By…

runc security bypass | CVE-2023-28642

NAME__________runc security bypassPlatforms Affected:Open Container Initiative runc 1.1.4Risk Level:6.1Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________runc could allow a remote attacker to bypass security restrictions, caused by a symbolic link following vulnerability. By creating a…

Nextcloud iOS app security bypass | CVE-2023-28647

NAME__________Nextcloud iOS app security bypassPlatforms Affected:Nextcloud iOS app 4.6.0Risk Level:4.4Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Nextcloud iOS app could allow a physical authenticated attacker to bypass security restrictions, caused by improper authentication validation. By…

Nextcloud Server security bypass | CVE-2023-28643

NAME__________Nextcloud Server security bypassPlatforms Affected:Nextcloud Nextcloud Server 25.0.0Risk Level:5.5Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Nextcloud Server could allow a remote authenticated attacker to bypass security restrictions, caused by a flaw when a recipient receives…

lambdaisland/uri security bypass | CVE-2023-28628

NAME__________lambdaisland/uri security bypassPlatforms Affected:lambdaisland/uri lambdaisland/uri 1.13.95Risk Level:5.4Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________lambdaisland/uri could allow a remote attacker to bypass security restrictions, caused by a flaw with authority-regex function returns the wrong authority. By…

Hitachi SDM600 security bypass | CVE-2022-3683

NAME__________Hitachi SDM600 security bypassPlatforms Affected:Hitachi Energy SDM600Risk Level:7.7Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Hitachi SDM600 could allow a remote authenticated attacker to bypass security restrictions, caused by a flaw in the API web services…

Hitachi SDM600 security bypass | CVE-2022-3686

NAME__________Hitachi SDM600 security bypassPlatforms Affected:Hitachi Energy SDM600Risk Level:4.8Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Hitachi SDM600 could allow a remote attacker to bypass security restrictions, caused by a flaw in API permission check mechanism. By…

lambdaisland/uri security bypass | CVE-2023-28628

NAME__________lambdaisland/uri security bypassPlatforms Affected:lambdaisland/uri lambdaisland/uri 1.13.95Risk Level:5.4Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________lambdaisland/uri could allow a remote attacker to bypass security restrictions, caused by a flaw with authority-regex function returns the wrong authority. By…

Nextcloud Server security bypass | CVE-2023-25818

NAME__________Nextcloud Server security bypassPlatforms Affected:Nextcloud Nextcloud Server 24.0.9 Nextcloud Nextcloud Server 25.0.3Risk Level:5Exploitability:UnprovenConsequences:Bypass Security DESCRIPTION__________Nextcloud Server could allow a remote attacker to bypass security restrictions, caused by missing brute force…