Weaknesses of type CWE-424

39 results

Proteção inadequada de caminhos alternativos

É quando a aplicação ou sistema protege um caminho de acesso (rota, endpoint, arquivo), mas deixa aberta uma rota alternativa que leva ao mesmo recurso sem as mesmas verificações de segurança. O atacante contorna a proteção usando a via não defendida.

Example

Um sistema bloqueia acesso a /admin/users, mas a mesma funcionalidade está acessível via /admin/../users ou através de um parâmetro não sanitizado que redireciona internamente. Ou um WAF bloqueia a requisição POST, mas a aplicação aceita PUT para a mesma ação.

How to mitigate

Identifique todos os caminhos que levam ao mesmo recurso (aliases, redirects, métodos HTTP alternativos, path traversal) e aplique as mesmas regras de acesso em todas elas. Não confie em validação apenas no endpoint principal — valide na lógica de negócio também.

CVE-2024-3459HIGHKioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened EPSS 0.3%CVE-2025-0113MEDIUMCortex XDR Broker VM: Unauthorized Access to Broker VM Docker ContainersEPSS 0.3%CVE-2025-46654MEDIUMCodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploadiEPSS 0.3%CVE-2025-46655MEDIUMCodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be byEPSS 0.2%CVE-2023-5165HIGHDocker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shellEPSS 0.2%CVE-2023-0629HIGHDocker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged containersEPSS 0.2%CVE-2024-8781HIGHContainer Escape Vulnerability in TR7's Application Security Platform (ASP)EPSS 0.2%CVE-2025-49162MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character alloEPSS 0.2%CVE-2023-46176MEDIUMIBM MQ privilege escalationEPSS 0.2%CVE-2023-52952CRITICALA vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (EPSS 0.2%CVE-2025-6250HIGHPrivilege Management for Windows - Elevation of PrivilegeEPSS 0.2%CVE-2025-49163MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.EPSS 0.2%CVE-2026-0237HIGHPrisma Browser: Improperly Restricted Automation Bridge Allows Security BypassEPSS 0.1%CVE-2025-4617LOWPrisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma BrowserEPSS 0.1%CVE-2026-4270MEDIUMAWS API MCP File Access Restriction BypassEPSS 0.1%CVE-2026-37008HIGHCrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVEEPSS 0.1%CVE-2022-24932MEDIUMImproper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker packageEPSS 0.1%CVE-2022-28782MEDIUMImproper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package befoEPSS 0.1%CVE-2026-0268MEDIUMPrisma Access Agent: Local Authenticated VPN Enforcement Bypass on LinuxEPSS 0.1%