Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2024-20297MEDIUMCisco Adaptive Security Appliance and Firepower Threat Defense AnyConnect Access Control List Bypass VulnerabilityEPSS 0.5%CVE-2024-20299MEDIUMCisco Adaptive Security Appliance and Firepower Threat Defense AnyConnect Access Control List Bypass VulnerabilityEPSS 0.5%CVE-2024-30480LOWWordPress CGC Maintenance Mode plugin <= 1.2 - IP Filtering Bypass vulnerabilityEPSS 0.5%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.5%CVE-2022-48349CRITICALThe control component has a spoofing vulnerability. Successful exploitation of this vulnerability may affect confidentiality and availabilitEPSS 0.5%CVE-2024-1555HIGHWhen opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects FirEPSS 0.5%CVE-2026-40575CRITICALOAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header SpoofingEPSS 0.5%CVE-2026-34457CRITICALOAuth2 Proxy: Health Check User-Agent Matching Bypasses Authentication in auth_request ModeEPSS 0.5%CVE-2024-1347MEDIUMAuthentication Bypass by Spoofing in GitLabEPSS 0.5%CVE-2023-36769MEDIUMMicrosoft OneNote Spoofing VulnerabilityEPSS 0.5%CVE-2023-51326MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessiveEPSS 0.5%CVE-2023-51327MEDIUMA lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cleaning Business Software v1.0 allows attackers to send an excessiveEPSS 0.5%CVE-2026-33433MEDIUMTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldEPSS 0.5%CVE-2025-1298CRITICALLogic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.EPSS 0.5%CVE-2022-38164MEDIUMA vulnerability affecting F-Secure SAFE browser for Android and iOS was discovered. A maliciously crafted website could make a phishing attaEPSS 0.5%CVE-2025-66507HIGH1Panel – CAPTCHA Bypass via Client-Controlled FlagEPSS 0.5%CVE-2026-30975HIGHSonarr Authentication Bypass vulnerabilityEPSS 0.5%CVE-2026-12382HIGHAap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofingEPSS 0.5%CVE-2024-11692MEDIUMAn attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks.EPSS 0.5%CVE-2026-45045MEDIUMFiber: X-Real-IP Spoofing via Header.Add() in BalancerForwardEPSS 0.5%