Weaknesses of type CWE-282

29 results

Gestão inadequada de proprietário de recursos

Ocorre quando um sistema não verifica ou não mantém corretamente quem é o proprietário de um recurso (arquivo, processo, conexão, objeto). Um atacante consegue acessar, modificar ou deletar recursos que não lhe pertencem porque o controle de proprietário é fraco ou inexistente, permitindo escalação de privilégio ou acesso não autorizado.

Example

Um aplicativo web cria arquivos temporários com permissões abertas (777) sem verificar se o usuário que está acessando é realmente o criador do arquivo. Um atacante consegue ler ou sobrescrever arquivos de outros usuários explorado essa brecha.

How to mitigate

Implemente verificação explícita de proprietário antes de qualquer operação em recurso (comparar UID/GID do proprietário com o usuário atual); use permissões restritivas por padrão (600 para arquivos, 700 para diretórios) e aplique controle de acesso baseado em papéis ou ACLs quando necessário.

CVE-2023-0386HIGHA flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the LinuxEPSS 7.9%KEVCVE-2026-23514HIGHKiteworks Core before 9.2.2 is vulnerable to Improper Ownership ManagementEPSS 1.0%CVE-2024-8949MEDIUMSourceCodester Online Eyewear Shop Cart Content Master.php improper ownership managementEPSS 0.7%CVE-2024-3383HIGHPAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)EPSS 0.6%CVE-2020-10632HIGHICSA-20-140-02 Emerson OpenEnterpriseEPSS 0.5%CVE-2022-29187HIGHBypass of safe.directory protections in GitEPSS 0.4%CVE-2023-7226MEDIUMmeetyoucrop big-whale Admin Module all.api improper ownership managementEPSS 0.4%CVE-2023-0989MEDIUMImproper Ownership Management in GitLabEPSS 0.4%CVE-2024-39755HIGHA privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lEPSS 0.4%CVE-2025-32946MEDIUMPeerTube Arbitrary Playlist Creation via ActivityPub ProtocolEPSS 0.4%CVE-2024-45103MEDIUMA valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileEPSS 0.3%CVE-2017-12189It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlinEPSS 0.3%CVE-2024-47816MEDIUMUsers can impersonate import requesters if their actor IDs coincide in ImportDumpEPSS 0.3%CVE-2025-32945MEDIUMPeerTube Arbitrary Playlist Creation via REST APIEPSS 0.3%CVE-2024-43176MEDIUMIBM OpenPages information disclosureEPSS 0.3%CVE-2024-13246MEDIUMNode Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010EPSS 0.3%CVE-2026-50130HIGHPi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`EPSS 0.3%CVE-2026-3867MEDIUMAn improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-EPSS 0.2%CVE-2025-67642MEDIUMJenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing aEPSS 0.2%CVE-2022-0026MEDIUMCortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%