CWE-639 · 2 471 записей
Обход авторизации через управляемый пользователем ключ
Почему это происходит?
Эндпоинт получает запись по идентификатору из запроса, но не проверяет, принадлежит ли она запрашивающему пользователю.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
const invoice = await Invoice.findById(req.params.id);res.json(invoice);Исправленный код
const invoice = await Invoice.findOne({ id: req.params.id, ownerId: req.user.id,});if (!invoice) return res.sendStatus(404);res.json(invoice);Как предотвратить
- 01Добавляйте пользователя текущей сессии как условие в каждый запрос.
- 02Сосредоточьте проверку владения в едином слое авторизации.
- 03Пишите тесты перекрёстного доступа с двумя разными учётными записями.
CVE этого класса
2 474 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
66На этой неделе | CVE-2023-6875Готовый эксплойт | POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app APIwpexperts · post smtp · CWE-639 | Критическая9,8 | — | 90,3 % | 11 янв. 2024 г. |
63На этой неделе | CVE-2026-55255Готовый эксплойт | Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flowlangflow · langflow · CWE-639 | Высокая8,4 | KEV | 0,9 % | 23 июн. 2026 г. |
56В плане | CVE-2021-45428Proof of concept | TLR-2005KSH is affected by an incorrect access control vulnerability.telesquare · tlr-2005ksh firmware · CWE-639 | Критическая9,8 | — | 56,9 % | 3 янв. 2022 г. |
52В плане | CVE-2019-17382Proof of concept | An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.zabbix · zabbix · CWE-639 | Критическая9,1 | — | 54,2 % | 9 окт. 2019 г. |
48В плане | CVE-2024-46982Proof of concept | Cache Poisoning in next.jsvercel · next.js · CWE-639 | Высокая7,5 | — | 59,2 % | 17 сент. 2024 г. |
47В плане | CVE-2025-2563Готовый эксплойт | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalationwpeverest · user registration \& membership · CWE-639 | Высокая8,1 | — | 48,8 % | 14 апр. 2025 г. |
46В плане | CVE-2019-13360Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging kcontrol-webpanel · webpanel · CWE-639 | Критическая9,8 | — | 24,5 % | 16 июл. 2019 г. |
44В плане | CVE-2024-0264Эксплойта нет | SourceCodester Clinic Queuing System LoginRegistration.php authorizationoretnom23 · clinic queuing system · CWE-639 | Критическая9,8 | — | 18,2 % | 7 янв. 2024 г. |
43В плане | CVE-2022-22832Proof of concept | An issue was discovered in Servisnet Tessa 0.0.2.servisnet · tessa · CWE-639 | Критическая9,8 | — | 14,1 % | 6 февр. 2022 г. |
41В плане | CVE-2025-3605Proof of concept | Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeoverarkenon · login, registration and lost password blocks · CWE-639 | Критическая9,8 | — | 6,9 % | 9 мая 2025 г. |
40В плане | CVE-2019-13605Proof of concept | In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process bycontrol-webpanel · webpanel · CWE-639 | Высокая8,8 | — | 15,3 % | 16 июл. 2019 г. |
40В плане | CVE-2019-6716Proof of concept | An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a rlogonbox · nervepoint access manager · CWE-639 | Критическая9,4 | — | 9,6 % | 21 мар. 2019 г. |
40В плане | CVE-2025-5947Proof of concept | Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookieaonetheme · service finder bookings · CWE-639 | Критическая9,8 | — | 4,4 % | 1 авг. 2025 г. |
40В плане | CVE-2022-31692Proof of concept | Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or includvmware · spring security · CWE-639 | Критическая9,8 | — | 3,6 % | 31 окт. 2022 г. |
40В плане | CVE-2020-11658Эксплойта нет | CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.broadcom · ca api developer portal · CWE-639 | Критическая9,8 | — | 2,4 % | 15 апр. 2020 г. |
40В плане | CVE-2024-50483Proof of concept | WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerabilitytareqhasan · meetup · CWE-639 | Критическая9,8 | — | 2,3 % | 28 окт. 2024 г. |
40В плане | CVE-2022-0691Эксплойта нет | Authorization Bypass Through User-Controlled Key in unshiftio/url-parseurl-parse project · url-parse · CWE-639 | Критическая9,8 | — | 2,2 % | 21 февр. 2022 г. |
40В плане | CVE-2019-9756Эксплойта нет | An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6, gitlab · gitlab · CWE-639 | Критическая9,8 | — | 2,2 % | 17 апр. 2019 г. |
40В плане | CVE-2019-12866Эксплойта нет | An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack.jetbrains · youtrack · CWE-639 | Критическая9,8 | — | 1,9 % | 3 июл. 2019 г. |
40В плане | CVE-2025-14998Proof of concept | Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeoverwpmudev · branda – white label & branding, free login page customizer · CWE-639 | Критическая9,8 | — | 1,9 % | 1 янв. 2026 г. |
40В плане | CVE-2026-83711Эксплойта нет | Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerabilitymicrosoft · entra · CWE-639 | Критическая10,0 | — | 0,8 % | 3 сент. 2026 г. |
40В плане | CVE-2026-69865Эксплойта нет | Microsoft Container Registry Elevation of Privilege Vulnerabilitymicrosoft · azure container registry · CWE-639 | Критическая10,0 | — | 0,8 % | 17 сент. 2026 г. |
40В плане | CVE-2024-45032Эксплойта нет | A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versisiemens · industrial edge management pro · CWE-639 | Критическая10,0 | — | 0,8 % | 10 сент. 2024 г. |
40В плане | CVE-2025-40805Эксплойта нет | Affected devices do not properly enforce user authentication on specific API endpoints.siemens · industrial edge cloud device (iecd) · CWE-639 | Критическая10,0 | — | 0,7 % | 13 янв. 2026 г. |
40В плане | CVE-2026-77998Эксплойта нет | Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – Lminiorange.com · saml sso free for joomla extension for joomla · CWE-639 | Критическая10,0 | — | 0,6 % | 25 авг. 2026 г. |
- CVE-2023-687566На этой неделе
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
КритическаяCVSS 9,8Готовый эксплойтEPSS 90 %wpexperts · post smtp11 янв. 2024 г.
- CVE-2026-5525563На этой неделе
Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow
ВысокаяCVSS 8,4KEVГотовый эксплойтEPSS 1 %langflow · langflow23 июн. 2026 г.
- CVE-2021-4542856В плане
TLR-2005KSH is affected by an incorrect access control vulnerability.
КритическаяCVSS 9,8Proof of conceptEPSS 57 %telesquare · tlr-2005ksh firmware3 янв. 2022 г.
- CVE-2019-1738252В плане
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4.
КритическаяCVSS 9,1Proof of conceptEPSS 54 %zabbix · zabbix9 окт. 2019 г.
- CVE-2024-4698248В плане
Cache Poisoning in next.js
ВысокаяCVSS 7,5Proof of conceptEPSS 59 %vercel · next.js17 сент. 2024 г.
- CVE-2025-256347В плане
User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
ВысокаяCVSS 8,1Готовый эксплойтEPSS 49 %wpeverest · user registration \& membership14 апр. 2025 г.
- CVE-2019-1336046В плане
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, remote attackers can bypass authentication in the login process by leveraging k
КритическаяCVSS 9,8Proof of conceptEPSS 24 %control-webpanel · webpanel16 июл. 2019 г.
- CVE-2024-026444В плане
SourceCodester Clinic Queuing System LoginRegistration.php authorization
КритическаяCVSS 9,8Эксплойта нетEPSS 18 %oretnom23 · clinic queuing system7 янв. 2024 г.
- CVE-2022-2283243В плане
An issue was discovered in Servisnet Tessa 0.0.2.
КритическаяCVSS 9,8Proof of conceptEPSS 14 %servisnet · tessa6 февр. 2022 г.
- CVE-2025-360541В плане
Frontend Login and Registration Blocks <= 1.1.1 - Unauthenticated Privilege Escalation via Account Takeover
КритическаяCVSS 9,8Proof of conceptEPSS 7 %arkenon · login, registration and lost password blocks9 мая 2025 г.
- CVE-2019-1360540В плане
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in the login process by
ВысокаяCVSS 8,8Proof of conceptEPSS 15 %control-webpanel · webpanel16 июл. 2019 г.
- CVE-2019-671640В плане
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 through 2017 allows a r
КритическаяCVSS 9,4Proof of conceptEPSS 10 %logonbox · nervepoint access manager21 мар. 2019 г.
- CVE-2025-594740В плане
Service Finder Bookings <= 6.0 - Authentication Bypass via User Switch Cookie
КритическаяCVSS 9,8Proof of conceptEPSS 4 %aonetheme · service finder bookings1 авг. 2025 г.
- CVE-2022-3169240В плане
Spring Security, versions 5.7 prior to 5.7.5 and 5.6 prior to 5.6.9 could be susceptible to authorization rules bypass via forward or includ
КритическаяCVSS 9,8Proof of conceptEPSS 4 %vmware · spring security31 окт. 2022 г.
- CVE-2020-1165840В плане
CA API Developer Portal 4.3.1 and earlier handles shared secret keys in an insecure manner, which allows attackers to bypass authorization.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %broadcom · ca api developer portal15 апр. 2020 г.
- CVE-2024-5048340В плане
WordPress Meetup plugin <= 0.1 - Broken Authentication vulnerability
КритическаяCVSS 9,8Proof of conceptEPSS 2 %tareqhasan · meetup28 окт. 2024 г.
- CVE-2022-069140В плане
Authorization Bypass Through User-Controlled Key in unshiftio/url-parse
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %url-parse project · url-parse21 февр. 2022 г.
- CVE-2019-975640В плане
An issue was discovered in GitLab Community and Enterprise Edition 10.x (starting from 10.8) and 11.x before 11.6.10, 11.7.x before 11.7.6,
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %gitlab · gitlab17 апр. 2019 г.
- CVE-2019-1286640В плане
An Insecure Direct Object Reference, with Authorization Bypass through a User-Controlled Key, was possible in JetBrains YouTrack.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %jetbrains · youtrack3 июл. 2019 г.
- CVE-2025-1499840В плане
Branda – White Label & Branding, Free Login Page Customizer <= 3.4.24 - Unauthenticated Privilege Escalation via Account Takeover
КритическаяCVSS 9,8Proof of conceptEPSS 2 %wpmudev · branda – white label & branding, free login page customizer1 янв. 2026 г.
- CVE-2026-8371140В плане
Microsoft Azure Active Directory B2C Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microsoft · entra3 сент. 2026 г.
- CVE-2026-6986540В плане
Microsoft Container Registry Elevation of Privilege Vulnerability
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %microsoft · azure container registry17 сент. 2026 г.
- CVE-2024-4503240В плане
A vulnerability has been identified in Industrial Edge Management Pro (All versions < V1.9.5), Industrial Edge Management Virtual (All versi
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · industrial edge management pro10 сент. 2024 г.
- CVE-2025-4080540В плане
Affected devices do not properly enforce user authentication on specific API endpoints.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %siemens · industrial edge cloud device (iecd)13 янв. 2026 г.
- CVE-2026-7799840В плане
Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML SSO < 11.0.2, SAML SP Single Sign On – L
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %miniorange.com · saml sso free for joomla extension for joomla25 авг. 2026 г.