Threats Tagged 'cwe-283'
View all threats tagged with 'cwe-283'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-283'
Click on any threat for detailed analysis and mitigation recommendations
Unverified ownership in Barman snapshot backup deletion allows a principal who can write the backup catalog to cause Barman to delete unrelated cloud snapshots. When a snapshot backup is deleted, either explicitly or by retention policy enforcement, Barman reads the snapshot identifiers from the backup.info file and passes them to the cloud provider's delete API using Barman's own credentials, without verifying that the snapshots belong to that backup. An attacker who can overwrite backup.info but lacks snapshot delete permissions can substitute the identifiers of other snapshots, causing Barman to delete any snapshot its cloud identity can reach on AWS, Microsoft Azure, or Google Cloud. Exploitation requires a deployment where the principal that writes the backup catalog is separate from the identity Barman uses to delete snapshots. Barman versions from 3.4.0 (Google Cloud), 3.6.0 (Azure), and 3.7.0 (AWS) up to and including 3.20.0 are affected. The issue is fixed in Barman 3.20.1. Join the discussion | CVE Database V5 | 09/29/2026, 20:55:51 UTC Added: 09/29/2026, 21:07:09 UTC |
gitoxide is an implementation of git written in Rust. Prior to 0.13.3, the gix-sec crate on Windows incorrectly treats repositories controlled by another user as trusted when an administrator runs a dependent program with an unfiltered elevated token. In gix-sec/src/identity.rs, gix_sec::identity::is_path_owned_by_current_user obtains folder_owner and token_owner, but its administrator-specific IsWellKnownSid and CheckTokenMembership checks examine the running token rather than confirming the directory owner. This bypasses safe.directory-style protection for repositories owned and configured by a limited user, allowing repository configuration or hooks to execute commands with the administrator's privileges when an affected operation is performed. Exploitation requires Windows, an elevated administrator, a program that relies on gix-sec trust results, and interaction with a repository controlled by another user. An unelevated UAC process is not affected, and cloning is not affected because repository configuration and hooks are not copied. This issue is fixed in version 0.13.3. Join the discussion | CVE Database V5 | 09/14/2026, 15:28:03 UTC Added: 09/14/2026, 15:32:02 UTC |
A missing S3 bucket ownership verification in the AWS Security Agent MCP server before 0.2.0 version might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 0.2.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered. Join the discussion | CVE Database V5 | 09/10/2026, 15:43:11 UTC Added: 09/10/2026, 15:49:33 UTC |
A missing S3 bucket ownership verification in the AWS Security Agent plugin in Amazon aws-agents-for-devsecops before 1.1.0 might allow remote attackers to obtain the private source archive of a scanned workspace, including credentials and infrastructure state contained in that archive, via a pre-registered storage bucket whose name is derived from a publicly known account identifier. To remediate this issue, users should upgrade to version 1.1.0. Users should also verify that the scan output bucket in their account is owned by their own account, because upgrading does not release a bucket name that a third party has already registered. Join the discussion | CVE Database V5 | 09/10/2026, 15:42:11 UTC Added: 09/10/2026, 15:49:33 UTC |
Unverified ownership of a storage access point in the volume deletion component of the Amazon EFS CSI Driver before v3.4.1 might allow an authenticated Kubernetes user with PersistentVolume creation privileges to cause recursive deletion of directories on an EFS filesystem they are not authorized to access, via a crafted PersistentVolume volumeHandle that pairs an access point from one filesystem with a different target filesystem. To remediate this issue, users should upgrade to version v3.4.1. Join the discussion | CVE Database V5 | 09/04/2026, 18:49:53 UTC Added: 09/04/2026, 18:52:41 UTC |
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket under their control. Join the discussion | CVE Database V5 | 09/03/2026, 20:41:34 UTC Added: 09/03/2026, 20:52:51 UTC |
CVE-2026-54467 is a high-severity vulnerability in Trusted Firmware-M versions 2 through 2.3.0 before commit 00d1b3e. It involves mailbox initialization on PSOC64 and RP2350 platforms accepting a non-secure, unvalidated pointer, leading to unverified ownership issues. Join the discussion | CVE Database V5 | 08/26/2026, 04:03:15 UTC Added: 08/26/2026, 04:22:46 UTC |
0 Bulletin ID: 2026-008-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/03/16 11:15 AM PDT Description: A missing S3 ownership verification in the Bedrock AgentCore Starter Toolkit before version v0.1.13 may allow a remote actor to inject code during the build process, leading to code execution in the AgentCore Runtime. Impacted versions: All versions of Bedrock AgentCore Starter Toolkit versions before v0.1.13. This issue only affects users of the Bedrock AgentCore Starter Toolkit before version v0.1.13 who build the Toolkit after September 24, 2025. Any users on a version >=v0.1.13, and any users on previous versions who built the toolkit before September 24, 2025 are not affected. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. Join the discussion | CVE Database V5 | 08/20/2026, 21:35:57 UTC Added: 03/16/2026, 18:20:50 UTC |
0 CVE-2026-15599 is an unverified ownership vulnerability in the pardus-domain-joiner software developed by TÜBİTAK BİLGEM Software Technologies Research Institute. This flaw allows privilege abuse due to improper verification of ownership. It affects versions prior to 0.5.5. The vulnerability has a low severity rating with a CVSS score of 3.3 and does not impact confidentiality or integrity but may affect availability. No official patch or remediation guidance has been published yet. Join the discussion | CVE Database V5 | 08/06/2026, 12:37:22 UTC Added: 08/06/2026, 13:12:00 UTC |
0 Bulletin ID: AWS-2025-026 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/11/6 09:15 AM PDT Description: Research and Engineering Studio on AWS (RES) is an open source, easy-to-use web-based portal for administrators to create and manage secure cloud-based research and engineering environments. We identified CVE-2025-12815, in which an ownership verification issue in the Virtual Desktop preview page in the Research and Engineering Studio (RES) on AWS before version 2025.09 may allow an authenticated remote user to view another user's active desktop session metadata, including periodical desktop preview screenshots. Impacted versions: < 2025.09 Join the discussion | CVE Database V5 | 06/05/2026, 19:19:25 UTC Added: 11/06/2025, 17:23:59 UTC |
Showing 1 to 10 of 15 results