GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass iss
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leadi
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possibl
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-pu
BigTree 4.3 allows full path disclosure via authenticated admin/news/ input that triggers a syntax error. NOTE: This has
Multiple versions of GitLab expose sensitive user credentials when assigning a user to an issue or merge request. A fix
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of anoth
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove columns from a private project of ano
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new category to a private project of a
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit metadata of a private project of anothe
In Kanboard before 1.0.47, by altering form data, an authenticated user can add a new task to a private project of anoth
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tags of a private project of another us
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit columns of a private project of another
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove categories from a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can add automatic actions to a private project o
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an internal link to a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another u
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove automatic actions from a private proj
In Kanboard before 1.0.47, by altering form data, an authenticated user can remove attachments from a private project of
In Kanboard before 1.0.47, by altering form data, an authenticated user can add an external link to a private project of
Frequently Asked Questions
What is CWE-639?
CWE-639 (CWE-639) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-639?
There are 2,673 CVE records associated with CWE-639 in our database. Of these, 174 are critical severity, 645 are high severity, and 1343 are medium severity.
How can I protect against CWE-639 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-639 using AI-powered security agents.
Detect CWE-639 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-639 vulnerabilities across your infrastructure.
Get Started