Weaknesses of type CWE-441

159 results

Deputado Confuso (Proxy ou Intermediário Não Intencional)

Quando um componente intermediário (servidor, API, função, etc.) executa ações em nome de um cliente sem validar adequadamente quem realmente autorizou aquela ação, um atacante consegue explorar a confiança já estabelecida entre esse intermediário e outros sistemas. O intermediário acaba agindo como 'procurador involuntário' do atacante, realizando operações que o sistema final nunca autorizaria se a requisição viesse diretamente do atacante.

Example

Um servidor de cache proxy que aceita requisições GET de qualquer origem e as repassa a um serviço interno sem verificar se o cliente original deveria ter acesso àqueles dados. Um atacante faz o proxy buscar informações sensíveis do servidor interno e devolver para si, usando a confiança que o servidor interno tem no proxy.

How to mitigate

Valide a identidade e autorização do cliente original antes de repassar requisições para sistemas internos; use tokens ou assinaturas criptográficas que viagem junto com a requisição; implemente listas de origem segura (whitelist) rigorosas e autenticação mútua entre componentes intermediários e backends.

CVE-2024-9870MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in GitLabEPSS 0.4%CVE-2026-45723LOWOmni: Operator can traverse image-factory API paths via unsanitized `talos_version` in CreateSchematicEPSS 0.4%CVE-2026-44945CRITICALCross-Cluster Impersonation Confused-Deputy Privilege EscalationEPSS 0.4%CVE-2025-48710MEDIUMkro (Kube Resource Orchestrator) 0.1.0 before 0.2.1 allows users (with permission to create or modify ResourceGraphDefinition resources) to EPSS 0.4%CVE-2026-87582HIGHConfused deputy in DataTransfer in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process tEPSS 0.4%CVE-2026-17107HIGHCluster-proxy: impersonation-header injection grants cluster-admin on every managed clusterEPSS 0.3%CVE-2026-54628HIGHAnyquery: Server-Side Request Forgery (SSRF) via Unrestricted SQLite Virtual Table Modules in Server ModeEPSS 0.3%CVE-2023-33188MEDIUM Uncontrolled data used in content resolution EPSS 0.3%CVE-2026-33768MEDIUMAstro: Unauthenticated Path Override via `x-astro-path` / `x_astro_path`EPSS 0.3%CVE-2026-24471CRITICALImproper Validation in Conduit-derived homeservers resulting in Unintended Proxy or Intermediary ('Confused Deputy')EPSS 0.3%CVE-2026-70398CRITICALMulticloud-integrations: multicloud-integrations: gitopscluster.spec.argoserver.argonamespace writes spoke bearer tokens to attacker-chosen namespaceEPSS 0.3%CVE-2026-6993MEDIUMgo-kratos http.DefaultServeMux Fallback server.go NewServer confused deputyEPSS 0.3%CVE-2026-15183CRITICALInput Validation Vulnerabilities in Snowflake Spark ConnectorEPSS 0.3%CVE-2025-64123HIGHNuvation Energy Multi-Stack Controller Proxy service allows arbitrary BMS accessEPSS 0.3%CVE-2026-73079HIGHSub2API: Path traversal in the Responses subpath routes lets an authenticated tenant relay requests to arbitrary upstream endpoints using pooled account credentialsEPSS 0.3%CVE-2026-16456MEDIUMOdh-model-controller: odh-model-controller: cross-namespace secret read via nim account crd confused deputyEPSS 0.3%CVE-2026-86600HIGHWorkload identity attestation generated before login host validation in Snowflake driversEPSS 0.3%CVE-2026-69531MEDIUMMicrosoft Windows Speech Tampering VulnerabilityEPSS 0.3%CVE-2026-43910HIGHAppium java-client Allows Network Pivot via Unvalidated directConnect Redirect in AppiumCommandExecutorEPSS 0.3%CVE-2026-27624HIGHCoturn: IPv4-mapped IPv6 (::ffff:0:0/96) bypasses denied-peer-ip ACLEPSS 0.3%