Weaknesses of type CWE-281

225 results

Preservação inadequada de permissões

Ocorre quando uma aplicação cria, copia ou modifica arquivos, processos ou recursos sem manter ou validar as permissões de acesso originais. Isso permite que usuários não autorizados acessem dados sensíveis ou executem operações privilégiadas que deveriam estar restritas.

Example

Um backup de banco de dados é criado com permissões world-readable porque o código copia o arquivo sem preservar o mode 0600 do original, expondo credenciais de produção a qualquer usuário do servidor. Ou um processo filho herda mais privilégios que deveria porque o pai não descarta capabilities do Linux antes de exec().

How to mitigate

Sempre defina explicitamente permissões restritivas ao criar ou copiar recursos sensíveis (chmod 0600 para arquivos, setfacl para ACLs). Valide permissões antes de acessar e remova privilégios desnecessários antes de executar código não confiável (chown, chgrp, umask consciente).

CVE-2024-54557HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2EPSS 0.5%CVE-2022-31096MEDIUMInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in DiscourseEPSS 0.5%CVE-2024-22404MEDIUMPermissions bypass in Nextcloud with the files zip appEPSS 0.5%CVE-2024-54818HIGHSourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.EPSS 0.5%CVE-2024-22402MEDIUMImproper handling of request URLs in Nextcloud Guests app allows guest users to bypass app allowlistEPSS 0.5%CVE-2024-27795HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to aEPSS 0.5%CVE-2024-30187MEDIUMAnope before 2.0.15 does not prevent resetting the password of a suspended account.EPSS 0.5%CVE-2025-43698CRITICALImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for SEPSS 0.5%CVE-2024-41648HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2024-32882LOWPermission check bypass when editing a model with per-field restrictions in wagtailEPSS 0.5%CVE-2024-41650HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2021-3418If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validatiEPSS 0.5%CVE-2021-3847An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the wEPSS 0.5%CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2024-50920HIGHInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted EPSS 0.5%CVE-2021-21379HIGHIt's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macroEPSS 0.5%CVE-2024-36532CRITICALInsecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tEPSS 0.5%CVE-2024-33892MEDIUMInsecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible toEPSS 0.4%CVE-2025-25871HIGHAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.4%CVE-2023-42228HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL ruEPSS 0.4%