CWE-271
7 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-271page 1 of 1
- CVE-2019-11243HIGHCVSS 8.12019-04-22
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions…
- CVE-2020-35513MEDIUMCVSS 4.9EG 4.92021-01-26
A flaw incorrect umask during file or directory modification in the Linux kernel NFS (network file system) functionality was found in the way user create and delete object using NFSv4.2 or newer if both simultaneously accessing the NFS by …
- CVE-2022-3569HIGHCVSS 7.8EG 7.82022-10-17
Due to an issue with incorrect sudo permissions, Zimbra Collaboration Suite (ZCS) suffers from a local privilege escalation issue in versions 9.0.0 and prior, where the 'zimbra' user can effectively coerce postfix into running arbitrary co…
- CVE-2023-22648HIGHCVSS 8.0EG 8.02023-06-01
A Improper Privilege Management vulnerability in SUSE Rancher causes permission changes in Azure AD not to be reflected to users while they are logged in the Rancher UI. This would cause the users to retain their previous permissions in …
- CVE-2023-38496MEDIUMCVSS 6.1EG 6.12023-07-25
Apptainer is an open source container platform. Version 1.2.0-rc.2 introduced an ineffective privilege drop when requesting container network setup, therefore subsequent functions are called with root privileges, the attack surface is rath…
- CVE-2024-0985HIGHCVSS 8.0EG 8.02024-02-08
Late privilege drop in REFRESH MATERIALIZED VIEW CONCURRENTLY in PostgreSQL allows an object creator to execute arbitrary SQL functions as the command issuer. The command intends to run SQL functions as the owner of the materialized view, …
- CVE-2024-35179MEDIUMCVSS 6.8EG 6.82024-05-15
Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to r…
Map vulnerabilities like CWE-271 to your infrastructure
EchelonGraph correlates every CVE — across CWE-271 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →