Перейти к содержимому
Noroxi

CWE-647 · 16 записей

Use of Non-Canonical URL Paths for Authorization Decisions

CVE этого класса

16 записей

  • CVE-2022-43939
    97Срочно

    Hitachi Vantara Pentaho Business Analytics Server - Use of Non-Canonical URL Paths for Authorization Decisions

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %

    hitachi · vantara pentaho business analytics server3 апр. 2023 г.

  • GHSA-f54f-hr32-586f
    37Наблюдать

    Duplicate Advisory: `allowed_domains` can be bypassed by putting a decoy domain in http auth username portion of a URL

    КритическаяCVSS 9,3Эксплойта нет

    PyPI · browser-use3 мая 2025 г.

  • CVE-2026-80515
    35Наблюдать

    In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 the management-authorization gate that protects every /…/mgmt/… REST endpoint decides whet

    ВысокаяCVSS 8,9Эксплойта нетEPSS 0 %

    eclipse foundation · eclipse arrowhead3 сент. 2026 г.

  • CVE-2026-62685
    32Наблюдать

    File Browser: Colliding username normalization gives two users the same home directory

    ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %

    filebrowser · filebrowser15 июл. 2026 г.

  • CVE-2026-59731
    32Наблюдать

    Astro 6.4.7 Authorization Bypass via Decode Iteration Limit and Rewrite Path Canonicalization Mismatch

    ВысокаяCVSS 8,2Эксплойта нетEPSS 0 %

    withastro · astro8 июл. 2026 г.

  • CVE-2025-64500
    29Наблюдать

    Symfony's incorrect parsing of PATH_INFO can lead to limited authorization bypass

    ВысокаяCVSS 7,3Proof of conceptEPSS 1 %

    sensiolabs · httpfoundation12 нояб. 2025 г.

  • CVE-2025-66202
    26Наблюдать

    Astro has an Authentication Bypass via Double URL Encoding, a bypass for CVE-2025-64765

    СредняяCVSS 6,5Эксплойта нетEPSS 0 %

    astro · astro8 дек. 2025 г.

  • CVE-2025-9909
    26Наблюдать

    Aap-gateway: improper path validation in gateway allows credential exfiltration

    СредняяCVSS 6,7Эксплойта нетEPSS 0 %

    redhat · ansible automation platform27 февр. 2026 г.

  • GHSA-c534-2w9c-x7fm
    26Наблюдать

    Kite Kubernetes proxy path traversal allows authenticated users to bypass RBAC and read cluster-wide resources

    СредняяCVSS 6,5Эксплойта нет

    Go · github.com/zxh326/kite24 июл. 2026 г.

  • CVE-2026-73551
    21Наблюдать

    Envoy: Path normalization does not handle dot and dotdot segments with parameters

    СредняяCVSS 5,3Эксплойта нетEPSS 1 %

    envoyproxy · envoy21 сент. 2026 г.

  • CVE-2026-8384
    21Наблюдать

    In Eclipse Jetty, an HTTP URI of this form: /public;/../admin/secret.txt results in an unresolved path of: /public/../admi

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    eclipse · jetty14 июл. 2026 г.

  • CVE-2025-47241
    16Наблюдать

    In browser-use (aka Browser Use) before 0.1.45, URL parsing of allowed_domains is mishandled because userinfo can be placed in the authority

    СредняяCVSS 4,0Эксплойта нетEPSS 0 %

    browser-use · browser-use3 мая 2025 г.

  • CVE-2026-15970
    16Наблюдать

    L7 intention authorization bypass via custom public listener

    СредняяCVSS 4,2Эксплойта нетEPSS 0 %

    hashicorp · consul7 авг. 2026 г.

  • CVE-2026-71178
    14Наблюдать

    Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Paths for Authorization

    НизкаяCVSS 3,7Эксплойта нетEPSS 0 %

    dell · policy manager for secure connect gateway6 дней назад

  • CVE-2025-43916
    13Наблюдать

    Sonos api.sonos.com through 2025-04-21, when the /login/v3/oauth endpoint is used, accepts a redirect_uri containing userinfo in the authori

    НизкаяCVSS 3,4Эксплойта нетEPSS 0 %

    sonos · api.sonos.com21 апр. 2025 г.

  • CVE-2026-5222
    9Наблюдать

    Cargo can be coerced to share credentials between registries

    НизкаяCVSS 2,3Эксплойта нетEPSS 0 %

    rust-lang · cargo25 мая 2026 г.

Все классы уязвимостей