CVEbaza.plSłownik CWECWE-708
Common Weakness Enumeration

CWE-708

Incorrect Ownership Assignment

Kategoria: BaseCVE: 21
Opis

Produkt przypisuje właściciela do zasobu, ale właściciel znajduje się poza zamierzoną sferą kontroli. Może to prowadzić do nieautoryzowanego dostępu lub manipulacji zasobem przez osoby spoza zamierzonej grupy kontrolującej.

Description (EN)

The product assigns an owner to a resource, but the owner is outside of the intended control sphere.

Podatności CVE z CWE-708 (21)
8.1
CVSS
HIGH
CVE-2026-40196

HomeBox is a home inventory and organization system. Versions prior to 0.25.0 contain a vulnerability where the defaultGroup ID remained permanently assigned to a user after being invited to a group, even after their access to that group was revoked. While the web interface correctly enforced the access revocation and prevented the user from viewing or modifying the group's contents, the API did not. Because the original group ID persisted as the user's defaultGroup, and this value was not properly validated when the X-Tenant header was omitted, the user could still perform full CRUD operations on the group's collections through the API, bypassing the intended access controls. This issue has been fixed in version 0.25.0.

pub. 2026-04-17
8.1
CVSS
HIGH
CVE-2021-32689

Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2, if a user was able to reuse an earlier used username, they could get access to any chat message sent to the previous user with this username. The issue was patched in versions 11.2.2 and 11.3.0. As a workaround, don't allow users to choose usernames themselves. This is the default behaviour of Nextcloud, but some user providers may allow doing so.

pub. 2021-07-12
7.8
CVSS
HIGH
CVE-2024-52561

A privilege escalation vulnerability exists in the Snapshot functionality of Parallels Desktop for Mac version 20.1.1 (build 55740). When a snapshot of a virtual machine is deleted, a root service verifies and modifies the ownership of the snapshot files. By using a symlink, an attacker can change the ownership of files owned by root to a lower-privilege user, potentially leading to privilege escalation.

pub. 2025-06-03
7.5
CVSS
HIGH
CVE-2022-33737

The OpenVPN Access Server installer creates a log file readable for everyone, which from version 2.10.0 and before 2.11.0 may contain a random generated admin password

pub. 2022-07-06
7.3
CVSS
HIGH
CVE-2022-22189

An Incorrect Ownership Assignment vulnerability in Juniper Networks Contrail Service Orchestration (CSO) allows a locally authenticated user to have their permissions elevated without authentication thereby taking control of the local system they are currently authenticated to. This issue affects: Juniper Networks Contrail Service Orchestration 6.0.0 versions prior to 6.0.0 Patch v3 on On-premises installations. This issue does not affect Juniper Networks Contrail Service Orchestration On-premises versions prior to 6.0.0.

pub. 2022-04-14
7.1
CVSS
HIGH
CVE-2021-32726

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

pub. 2021-07-12
6.7
CVSS
MEDIUM
CVE-2023-29122

Under certain conditions, access to service libraries is granted to account they should not have access to.

pub. 2024-11-05
6.7
CVSS
MEDIUM
CVE-2023-20043

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by calling the script with sudo. A successful exploit could allow the attacker to take complete control of the affected device.

pub. 2023-01-20
6.7
CVSS
MEDIUM
CVE-2023-20044

A vulnerability in Cisco CX Cloud Agent of could allow an authenticated, local attacker to elevate their privileges. This vulnerability is due to insecure file permissions. An attacker could exploit this vulnerability by persuading support to update settings which call the insecure script. A successful exploit could allow the attacker to take complete control of the affected device.

pub. 2023-01-20
6.5
CVSS
MEDIUM
CVE-2024-41773

IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.

pub. 2024-08-20
6.0
CVSS
MEDIUM
CVE-2024-45417

Uncontrolled resource consumption in the installer for some Zoom apps for macOS before version 6.1.5 may allow a privileged user to conduct a disclosure of information via local access.

pub. 2025-02-25
5.9
CVSS
MEDIUM
CVE-2021-26248

Philips MRI 1.5T and MRI 3T Version 5.3 through 5.8.1 does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

pub. 2021-11-19
5.3
CVSS
MEDIUM
CVE-2026-32691

Race condition w podsystemie zarządzania sekretami Juju w wersjach 3.0.0 do 3.6.18 pozwala uwierzytelnionemu agentowi unit na przejęcie własności nowo zainicjowanego sekretu. Między wygenerowaniem Juju Secret ID a utworzeniem pierwszej rewizji sekretu, atakujący uwierzytelniony jako inny agent unit może przejąć własność znanego sekretu. Umożliwia to atakującemu unitowi odczytanie zawartości początkowej rewizji sekretu.

pub. 2026-03-18
5.3
CVSS
MEDIUM
CVE-2025-14262

Nieprawidłowa kontrola uprawnień w KNIME Business Hub przed wersją 1.17.0 pozwalała uwierzytelnionemu użytkownikowi zapisywać zadania innych użytkowników tak, jakby były zapisane przez właściciela zadania. Atakujący musiał mieć uprawnienia dostępu do zadań, ale następnie były zapisywane do usługi catalog przy użyciu nieprawidłowych uprawnień właściciela, co mogło umożliwić zapis do przestrzeni, do których atakujący nie miał uprawnień do zapisu. Brak dostępnego obejścia.

pub. 2025-12-08
5.3
CVSS
MEDIUM
CVE-2023-4008

An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible to takeover GitLab Pages with unique domain URLs if the random string added was known.

pub. 2023-08-03
4.9
CVSS
MEDIUM
CVE-2024-45426

Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access.

pub. 2025-02-25
3.8
CVSS
LOW
CVE-2026-6469

Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE command reassigns ownership of dependent statistics objects to the current user. This wrongly allows the table owner to run DROP STATISTICS and ALTER STATISTICS via this improper ownership. It wrongly denies those commands to the prior statistics object owner. DROP TABLE remains able to remove statistics objects, so this exploit achieves nothing in many ownership arrangements. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

pub. 2026-08-13
3.7
CVSS
LOW
CVE-2023-41881

vantage6 to infrastruktura federated learning zabezpieczająca prywatność. Gdy kolaboracja zostaje usunięta, powiązane zasoby (takie jak zadania z tej kolaboracji) powinny być również usunięte. Jest to niezbędne zarówno do prawidłowego zarządzania danymi, jak i aby zapobiec potencjalnemu (choć mało prawdopodobnemu) efektowi ubocznyemu w wersjach wcześniejszych niż 4.0.0, gdzie usunięcie kolaboracji o id=10 i następnie utworzenie nowej kolaboracji z id=10 mogłoby pozwolić uwierzytelnionym użytkownikom na dostęp do wyników usuniętej kolaboracji w niektórych przypadkach. Wersja 4.0.0 zawiera patch dla tego problemu. Brak znanych obejść.

pub. 2023-10-11
3.5
CVSS
LOW
CVE-2025-5069

Odkryto podatność w GitLab CE/EE dotyczącą wszystkich wersji od 17.10 poprzedzających 18.2.7, 18.3 poprzedzających 18.3.3 i 18.4 poprzedzających 18.4.1, która mogła pozwolić uwierzytelnionemu użytkownikowi na uzyskanie nieautoryzowanego dostępu do poufnych issues poprzez utworzenie projektu o nazwie identycznej z projektem ofiary.

pub. 2025-09-26
3.1
CVSS
LOW
CVE-2024-9633

W GitLab CE/EE odkryto problem dotyczący wersji od 16.3 do 17.4.2, od 17.5 do 17.5.4 oraz od 17.6 do 17.6.2. Luka umożliwia atakującemu utworzenie grupy z nazwą odpowiadającą istniejącej unikalnej domenie Pages, co może prowadzić do domain confusion attacks.

pub. 2024-11-14
Pokazano 20 z 21 podatności
Informacje
ID: CWE-708
Typ: Base
Podatności: 21
MITRE CWE ↗
← Słownik CWE