Weaknesses of type CWE-732

791 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2024-8039CRITICALImproper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account taEPSS 0.4%CVE-2024-3668HIGHPowerPack Pro for Elementor <= 2.10.17 - Authenticated (Contributor+) Privilege EscalationEPSS 0.4%CVE-2018-14650MEDIUMIt was discovered that sos-collector does not properly set the default permissions of newly created files, making all files created by the tEPSS 0.4%CVE-2026-49340HIGHgonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the hostEPSS 0.4%CVE-2023-31238MEDIUMA vulnerability has been identified in SICAM P850 (7KG8500-0AA00-0AA0) (All versions < V3.11), SICAM P850 (7KG8500-0AA00-2AA0) (All versionsEPSS 0.4%CVE-2024-8900HIGHAn attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnEPSS 0.4%CVE-2023-33004MEDIUMA missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler stEPSS 0.4%CVE-2024-9142CRITICALLocal File Inclusion (LFI) in Olgu Computer Systems' e-BelediyeEPSS 0.4%CVE-2025-62575HIGHMirion Medical EC2 Software NMIS BioDose Incorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2024-25646HIGHInformation Disclosure vulnerability in SAP BusinessObjects Web IntelligenceEPSS 0.4%CVE-2026-42497HIGHArchive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directoryEPSS 0.4%CVE-2025-66723HIGHinMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attaEPSS 0.4%CVE-2024-41820MEDIUMCluster-level privilege escalation in kubeanEPSS 0.4%CVE-2026-61186CRITICALVulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version tEPSS 0.4%CVE-2025-31702MEDIUMA vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploiEPSS 0.4%CVE-2020-7337MEDIUMIncorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2024-25644MEDIUMInformation Disclosure vulnerability in NetWeaver (WSRM)EPSS 0.4%CVE-2024-25645MEDIUMInformation Disclosure vulnerability in SAP NetWeaver (Enterprise Portal)EPSS 0.4%CVE-2025-24009HIGHA vulnerability has been identified in SIRIUS 3RK3 Modular Safety System (MSS) (All versions), SIRIUS Safety Relays 3SK2 (All versions). TheEPSS 0.4%CVE-2022-21819HIGHNVIDIA distributions of Jetson Linux contain a vulnerability where an error in the IOMMU configuration may allow an unprivileged attacker wiEPSS 0.4%