CVEbaza.plSłownik CWECWE-304
Common Weakness Enumeration

CWE-304

Missing Critical Step in Authentication

Kategoria: BaseCVE: 40
Opis

Produkt implementuje technikę uwierzytelniania, ale pomija krok, który osłabia tę technikę. Pominięcie tego kroku prowadzi do znacznego obniżenia bezpieczeństwa procesu uwierzytelniania.

Description (EN)

The product implements an authentication technique, but it skips a step that weakens the technique.

Podatności CVE z CWE-304 (40)
9.8
CVSS
CRITICAL
CVE-2024-8954

Composio w wersji 0.5.10 nie weryfikuje wartości nagłówka `x-api-key` podczas uwierzytelniania, co umożliwia całkowite ominięcie mechanizmu ochrony dostępu. Podatność jest krytyczna, ponieważ nie wymaga żadnych uprawnień ani interakcji użytkownika i jest dostępna zdalnie przez sieć.

pub. 2025-03-20
9.8
CVSS
CRITICAL
CVE-2024-2172

Pluginy Malware Scanner oraz Web Application Firewall firmy MiniOrange dla WordPress zawierają krytyczną podatność umożliwiającą nieuwierzytelnionemu atakującemu uzyskanie uprawnień administratora. Brak sprawdzania uprawnień w funkcji mo_wpns_init() czyni tę podatność szczególnie niebezpieczną, gdyż nie wymaga żadnego uwierzytelnienia.

pub. 2024-03-13
9.8
CVSS
CRITICAL
CVE-2022-2302

Urządzenia z serii cabinet firmy Lenze pomijają weryfikację hasła podczas drugiego i kolejnych logowań, co umożliwia zdalny dostęp bez znajomości hasła. Podatność jest krytyczna, ponieważ nie wymaga żadnej interakcji użytkownika ani uprzedniego uwierzytelnienia po stronie atakującego.

pub. 2022-07-11
9.6
CVSS
CRITICAL
CVE-2026-44547

ChurchCRM w wersjach 7.2.0–7.2.2 pozostaje podatne na obejście uwierzytelnienia (Auth Bypass) z powodu niekompletnej poprawki dla CVE-2026-4058. Podatność ma ocenę CVSS 9.6 i jest aktywnie exploitowalna przy użyciu publicznie dostępnego PoC.

pub. 2026-05-12
9.1
CVSS
CRITICAL
CVE-2026-59564

An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal.

pub. 2026-08-24
9.1
CVSS
CRITICAL
CVE-2026-61466

W mechanizmie dynamicznej rejestracji klientów OAuth2 w Apache CXF serwer autoryzacji przyjmuje i zapisuje wartość pola `scope` z żądania rejestracyjnego bez weryfikacji z dozwoloną listą po stronie serwera. Umożliwia to atakującemu samodzielne przypisanie sobie uprzywilejowanych zakresów dostępu podczas rejestracji.

pub. 2026-08-06
9.0
CVSS
CRITICAL
CVE-2024-45764

Dell Enterprise SONiC OS w wersjach 4.1.x oraz 4.2.x zawiera podatność polegającą na pominięciu krytycznego kroku w procesie uwierzytelnienia (CWE-304). Nieuwierzytelniony atakujący z dostępem sieciowym może ominąć mechanizmy ochronne systemu bez podawania jakichkolwiek danych uwierzytelniających.

pub. 2024-11-08
8.8
CVSS
HIGH
CVE-2026-49467

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass password verification when managing Time-based One-Time Password (TOTP) settings. The root cause is a missing `await` keyword on calls to the asynchronous `verifyPassword` method in `authTotp.service.ts` and the `authenticateUser` method in `auth.service.ts`. In JavaScript, an unawaited `Promise` is always truthy. So the logic intended to throw a `ForbiddenException` when a password is incorrect. It never executes because the expression evaluates the existence of the `Promise` object rather than its resolved boolean result. The vulnerability is fixed in version 1.18.1 by ensuring all asynchronous authentication calls are properly awaited. There are no official workarounds. If a user is locked out, an administrator must manually reset the user's TOTP status in the database.

pub. 2026-08-12
8.8
CVSS
HIGH
CVE-2024-12048

An IDOR (Insecure Direct Object Reference) vulnerability exists in transformeroptimus/superagi version v0.0.14. The application fails to properly check authorization for multiple API endpoints, allowing attackers to view, edit, and delete other users' information without proper authorization. Affected endpoints include but are not limited to /get/project/{project_id}, /get/schedule_data/{agent_id}, /delete/{agent_id}, /get/organisation/{organisation_id}, and /get/user/{user_id}.

pub. 2025-03-20
8.8
CVSS
HIGH
CVE-2022-40622

The WAVLINK Quantum D4G (WN531G3) running firmware version M31G3.V5030.200325 uses IP addresses to hold sessions and does not not use session tokens. Therefore, if an attacker changes their IP address to match the logged-in administrator's, or is behind the same NAT as the logged in administrator, session takeover is possible.

pub. 2022-09-13
8.7
CVSS
HIGH
CVE-2026-67351

Serendipity przed wersją 2.6.1 zawiera podatność polegającą na błędzie kontekstu uwierzytelnienia, która pozwala zalogowanemu użytkownikowi z rolą Editor na uzyskanie uprawnień administratora. Błąd jest groźny, ponieważ nie wymaga znajomości hasła atakowanego konta Administrator.

pub. 2026-07-30
8.7
CVSS
HIGH
CVE-2019-16766

When using wagtail-2fa before 1.3.0, if someone gains access to someone's Wagtail login credentials, they can log into the CMS and bypass the 2FA check by changing the URL. They can then add a new device and gain full access to the CMS. This problem has been patched in version 1.3.0.

pub. 2019-11-29
8.6
CVSS
HIGH
CVE-2026-76207

phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes. Attackers with valid credentials can obtain a remember-me cookie, skip the 2FA challenge, and replay the cookie to gain full authenticated access without second-factor verification.

pub. 2026-08-19
8.1
CVSS
HIGH
CVE-2026-42452

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled accounts. That token carries a pendingTOTP state and should only be valid for the second-factor flow. However, the auth middleware accepts this token on regular authenticated endpoints. This effectively turns 2FA into single-factor (password) for impacted accounts. This issue has been patched in version 2.1.0.

pub. 2026-05-08
8.1
CVSS
HIGH
CVE-2025-24322

An unsafe default authentication vulnerability exists in the Initial Setup Authentication functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted network request can lead to arbitrary code execution. An attacker can browse to the device to trigger this vulnerability.

pub. 2025-08-20
8.1
CVSS
HIGH
CVE-2024-9216

An authentication bypass vulnerability exists in gaizhenbiao/ChuanhuChatGPT, as of commit 3856d4f, allowing any user to read and delete other users' chat history. The vulnerability arises because the username is provided via an HTTP request from the client side, rather than being read from a secure source like a cookie. This allows an attacker to pass another user's username to the get_model function, thereby gaining unauthorized access to that user's chat history.

pub. 2025-03-20
8.1
CVSS
HIGH
CVE-2022-1065

A vulnerability within the authentication process of Abacus ERP allows a remote attacker to bypass the second authentication factor. This issue affects: Abacus ERP v2022 versions prior to R1 of 2022-01-15; v2021 versions prior to R4 of 2022-01-15; v2020 versions prior to R6 of 2022-01-15; v2019 versions later than R5 (service pack); v2018 versions later than R5 (service pack). This issue does not affect: Abacus ERP v2019 versions prior to R5 of 2020-03-15; v2018 versions prior to R7 of 2020-04-15; v2017 version and prior versions and prior versions.

pub. 2022-04-19
8.0
CVSS
HIGH
CVE-2026-30831

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0, authentication vulnerabilities exist in Rocket.Chat's enterprise DDP Streamer service. The Account.login method exposed through the DDP Streamer does not enforce Two-Factor Authentication (2FA) or validate user account status (deactivated users can still login), despite these checks being mandatory in the standard Meteor login flow. This issue has been patched in versions 7.10.8, 7.11.5, 7.12.5, 7.13.4, 8.0.2, 8.1.1, and 8.2.0.

pub. 2026-03-06
8.0
CVSS
HIGH
CVE-2024-11302

A missing check_access() function in the lollms_binding_infos module of the parisneo/lollms repository, version V14, allows attackers to add, modify, and remove bindings arbitrarily. This vulnerability affects the /install_binding and /reinstall_binding endpoints, among others, enabling unauthorized access and manipulation of binding settings without requiring the client_id value.

pub. 2025-03-20
7.6
CVSS
HIGH
CVE-2023-22833

Palantir Foundry deployments running Lime2 versions between 2.519.0 and 2.532.0 were vulnerable a bug that allowed authenticated users within a Foundry organization to bypass discretionary or mandatory access controls under certain circumstances.

pub. 2023-06-06
Pokazano 20 z 40 podatności
Informacje
ID: CWE-304
Typ: Base
Podatności: 40
MITRE CWE ↗
← Słownik CWE