Weaknesses of type CWE-358

114 results

Verificação de Segurança Incompleta ou Inadequada

A aplicação implementa uma validação de segurança, mas ela é insuficiente, incompleta ou contornável — deixando brechas que um atacante consegue explorar. O código tenta proteger, mas falha em cobrir todos os cenários ou não valida corretamente, permitindo acesso não autorizado ou execução maliciosa.

Example

Um sistema valida se o usuário está autenticado antes de acessar um recurso, mas não verifica se ele tem permissão específica para aquele recurso; ou uma API verifica o token JWT, mas não valida a assinatura corretamente, permitindo tokens falsificados.

How to mitigate

Implemente validações em múltiplas camadas (autenticação + autorização), revise a lógica de segurança com testes de contorno, use bibliotecas consolidadas (OAuth 2.0, OWASP ESAPI) e realize code review focado em edge cases e cenários de bypass.

CVE-2021-34791MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass VulnerabilitiesEPSS 1.1%CVE-2021-34790MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass VulnerabilitiesEPSS 1.1%CVE-2026-44513HIGHDiffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom componentsEPSS 1.1%CVE-2023-28601HIGHZoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. EPSS 1.0%CVE-2023-3266CRITICALA non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checkEPSS 0.9%CVE-2024-3845CRITICALInappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy viEPSS 0.9%CVE-2019-14823MEDIUMA flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it impliEPSS 0.9%CVE-2024-6101HIGHInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory accessEPSS 0.8%CVE-2021-31375HIGHJunos OS: Receipt of a specific BGP update may cause RPKI policy-checks to be bypassedEPSS 0.8%CVE-2020-1728MEDIUMA vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing gEPSS 0.8%CVE-2023-4501CRITICALAuthentication bypass in OpenText (Micro Focus) Enterprise ServerEPSS 0.8%CVE-2024-3844MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crEPSS 0.7%CVE-2020-10743It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercEPSS 0.7%CVE-2023-40445HIGHThe issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17.1. A device may persistently fail to lock.EPSS 0.7%CVE-2023-2585LOWKeycloak: client access via device auth request spoofEPSS 0.7%CVE-2026-50628CRITICALApache CXF: OAuth2: Inverted IP Binding Check Defeats Security ControlEPSS 0.7%CVE-2022-38732HIGHSnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that oEPSS 0.7%CVE-2024-2617HIGHA vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature EPSS 0.7%CVE-2022-27219A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP EPSS 0.7%CVE-2022-27220A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP EPSS 0.7%