Weaknesses of type CWE-276

954 results

Permissões padrão incorretas

Ocorre quando um recurso (arquivo, diretório, banco de dados, serviço) é criado com permissões padrão excessivamente permissivas, expondo dados ou funcionalidades a usuários não autorizados. O desenvolvedor ou administrador não restringe explicitamente o acesso, deixando a configuração padrão do sistema, que geralmente é insegura.

Example

Um aplicativo cria arquivos de cache com informações sensíveis (tokens, chaves de API) com permissões 644 (leitura para todos), permitindo que qualquer usuário local da máquina leia esses dados. Ou um bucket S3 é criado com acesso público habilitado por padrão, expondo documentos confidenciais.

How to mitigate

Defina explicitamente permissões restritivas no código (ex: 0600 para arquivos sensíveis, 0700 para diretórios) e revise configurações padrão de infraestrutura antes do deploy. Automatize verificações de permissões em pipelines CI/CD e aplique o princípio do menor privilégio desde a criação dos recursos.

CVE-2023-31360HIGHIncorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow aEPSS 0.2%CVE-2022-26839HIGHDelta Electronics DIAEnergie Incorrect Default PermissionsEPSS 0.2%CVE-2022-3155HIGHWhen saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the recEPSS 0.2%CVE-2025-24135HIGHThis issue was addressed with improved message validation. This issue is fixed in macOS Sequoia 15.3. An app may be able to gain elevated prEPSS 0.2%CVE-2024-21820HIGHIncorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privilEPSS 0.2%CVE-2024-44135MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7. An app may be abEPSS 0.2%CVE-2021-33166MEDIUMIncorrect default permissions for the Intel(R) RXT for Chromebook application, all versions, may allow an authenticated user to potentially EPSS 0.2%CVE-2025-24176HIGHA permissions issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.3, macOS Sonoma 14.7.3, macOS Ventura 13EPSS 0.2%CVE-2024-25654MEDIUMInsecure permissions for log files of AVSystem Unified Management Platform (UMP) 23.07.0.16567~LTS allow members (with local access to the UEPSS 0.2%CVE-2023-7235HIGHThe OpenVPN GUI installer before version 2.6.9 did not set the proper access control restrictions to the installation directory of OpenVPN bEPSS 0.2%CVE-2022-31071LOWOctopoller gem published with world-writable filesEPSS 0.2%CVE-2022-31251MEDIUMslurm: %post for slurm-testsuite operates as root in user owned directoryEPSS 0.2%CVE-2026-18273MEDIUMKenwood DNR1007XR USB Incorrect Default Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2022-3466MEDIUMCri-o: security regression of cve-2022-27652EPSS 0.2%CVE-2022-23104MEDIUMWIN-911 2021 Incorrect Default PermissionsEPSS 0.2%CVE-2023-43629HIGHIncorrect default permissions in some Intel(R) GPA software installers before version 2023.3 may allow an authenticated user to potentially EPSS 0.2%CVE-2022-23922MEDIUMWIN-911 2021 Incorrect Default PermissionsEPSS 0.2%CVE-2023-3112HIGHA vulnerability was reported in Elliptic Labs Virtual Lock Sensor for ThinkPad T14 Gen 3 that could allow an attacker with local access to eEPSS 0.2%CVE-2020-8357MEDIUMA denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to bEPSS 0.2%CVE-2021-33129HIGHIncorrect default permissions in the software installer for the Intel(R) Advisor before version 2021.4.0 may allow an authenticated user to EPSS 0.2%