Weaknesses of type CWE-290

606 results

Autenticação insuficiente contra falsificação de identidade

Ocorre quando o mecanismo de autenticação falha em validar corretamente a identidade do usuário ou cliente, permitindo que um atacante se passe por outra pessoa. A implementação não implementa verificações robustas (como criptografia, assinaturas digitais ou desafios aleatórios), deixando a autenticação vulnerável a spoofing.

Example

Um sistema de API que valida usuários apenas pelo campo 'nome de usuário' em um cabeçalho HTTP sem usar token, sessão ou assinatura criptográfica — um atacante altera o header e acessa dados de outros usuários. Ou um protocolo que aceita certificados autoassinados sem verificar a cadeia de confiança, autenticando servidores falsos.

How to mitigate

Use mecanismos de autenticação estabelecidos e testados: tokens JWT com assinatura, OAuth 2.0, ou mTLS. Sempre valide criptograficamente a identidade do cliente, nunca confie em cabeçalhos ou cookies não assinados. Implemente desafios multi-fator e revogue credenciais comprometidas rapidamente.

CVE-2023-2887CRITICALUser Authentication Bypass in CBOT's ChatbotEPSS 0.8%CVE-2024-34397MEDIUMAn issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals frEPSS 0.8%CVE-2021-20278An authentication bypass vulnerability was found in Kiali in versions before 1.31.0 when the authentication strategy `OpenID` is used. When EPSS 0.8%CVE-2021-27853MEDIUML2 network filtering can be bypassed using stacked VLAN0 and LLC/SNAP headersEPSS 0.8%CVE-2025-32012MEDIUMJellyfin Vulnerable to Denial of Service (DoS) via IP SpoofingEPSS 0.8%CVE-2023-32207HIGHA missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerabiEPSS 0.7%CVE-2024-23674CRITICALThe Online-Ausweis-Funktion eID scheme in the German National Identity card through 2024-02-15 allows authentication bypass by spoofing. A mEPSS 0.7%CVE-2023-21794MEDIUMMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.7%CVE-2022-4746HIGHFluentAuth < 1.0.2 - Bypass blocks by IP SpoofingEPSS 0.7%CVE-2024-36466HIGHUnauthenticated Zabbix frontend takeover when SSO is being usedEPSS 0.7%CVE-2022-3820MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. GitLab was not pEPSS 0.7%CVE-2021-45036HIGHVelneo vClient improper authenticationEPSS 0.7%CVE-2023-48396CRITICALApache SeaTunnel Web: Authentication bypassEPSS 0.7%CVE-2026-58370CRITICALWoodpecker < 3.15.0 - GitLab Approval Gate Bypass via Spoofable Commit Author NameEPSS 0.7%CVE-2025-43245CRITICALA downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, mEPSS 0.7%CVE-2025-8853CRITICAL2100 Technology|Official Document Management System - Authentication BypassEPSS 0.7%CVE-2025-25182CRITICALStroom Authentication/Authorization Bypass when using AWS ALBEPSS 0.7%CVE-2026-55954CRITICALMissing ID token claim validation in ueberauth_apple allows account takeoverEPSS 0.7%CVE-2025-27695MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1 contain an Authentication Bypass by Spoofing vulnerability. A high privileged attackerEPSS 0.7%CVE-2024-49193HIGHZendesk before 2024-07-02 allows remote attackers to read ticket history via e-mail spoofing, because Cc fields are extracted from incoming EPSS 0.7%