Weaknesses of type CWE-290

607 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2024-8386MEDIUMIf a site had been granted the permission to open popup windows, it could cause Select elements to appear on top of another site to perform EPSS 0.4%CVE-2021-41130MEDIUMX-Endpoint-API-UserInfo can be spoofed in cloudendpoints Extensible Service ProxyEPSS 0.4%CVE-2026-28954HIGHA file quarantine bypass was addressed with additional checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, maEPSS 0.4%CVE-2024-4846MEDIUMAuthentication bypass in the 2FA feature in Devolutions Server 2024.1.14.0 and earlier allows an authenticated attacker to authenticate to aEPSS 0.4%CVE-2024-32827MEDIUMWordPress Giveaways and Contests by RafflePress plugin <= 1.12.7 - IP Restriction Bypass vulnerabilityEPSS 0.4%CVE-2026-45223HIGHCrabbox < 0.9.0 Authentication Bypass via Admin Claim InjectionEPSS 0.4%CVE-2026-24899HIGHFleet Windows MDM Azure AD JWT Authentication BypassEPSS 0.4%CVE-2026-55202HIGHTinyproxy - Stathost Detection Bypass via Host Header ManipulationEPSS 0.4%CVE-2026-77903CRITICALMicrosoft Dataverse Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-62235HIGHApache Mynewt NimBLE: Incorrect handling of SMP Security Request could lead to undesirable pairingEPSS 0.4%CVE-2025-3875HIGHSender Spoofing via Malformed From Header in ThunderbirdEPSS 0.4%CVE-2025-14327HIGHSpoofing issue in the Downloads Panel componentEPSS 0.4%CVE-2025-5067MEDIUMInappropriate implementation in Tab Strip in Google Chrome prior to 137.0.7151.55 allowed a remote attacker to perform UI spoofing via a craEPSS 0.4%CVE-2024-37430MEDIUMWordPress Patreon WordPress plugin <= 1.9.0 - Image Protection Bypass vulnerabilityEPSS 0.4%CVE-2025-56449HIGHA security vulnerability was identified in Obsidian Scheduler's REST API 5.0.0 thru 6.3.0. If an account is locked out due to not enrolling EPSS 0.4%CVE-2023-51543MEDIUMWordPress RegistrationMagic plugin <= 5.2.5.0 - IP Limit Bypass vulnerabilityEPSS 0.4%CVE-2026-8960HIGHSpoofing issue in WebExtensionsEPSS 0.4%CVE-2024-41432MEDIUMAn IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP adEPSS 0.4%CVE-2026-55210HIGHJoplin: SAML SSO account takeover via email-based account linking (missing is_external check in ssoLogin)EPSS 0.4%CVE-2025-31511HIGHAn issue was discovered in AlertEnterprise Guardian 4.1.14.2.2.1. One can bypass manager approval by changing the user ID in a Request%20BuiEPSS 0.4%