Weaknesses of type CWE-732

791 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2023-0834HIGHIncorrect Permission Assignment for Critical Resource vulnerability in HYPR Workforce Access on MacOS allows Privilege Escalation.This issueEPSS 0.4%CVE-2024-46897LOWIncorrect permission assignment for critical resource issue exists in Exment v6.1.4 and earlier and Exment v5.0.11 and earlier. A logged-in EPSS 0.4%CVE-2026-42812CRITICALApache Polaris: No protection on `write.metadata.path`EPSS 0.4%CVE-2025-27141MEDIUMMetabase Enterprise Edition allows cached questions to leak data to impersonated usersEPSS 0.4%CVE-2022-45305MEDIUMInsecure permissions in Chocolatey Python3 package v3.11.0 and below grants all users in the Authenticated Users group write privileges for EPSS 0.4%CVE-2022-45307MEDIUMInsecure permissions in Chocolatey PHP package v8.1.12 and below grants all users in the Authenticated Users group write privileges for the EPSS 0.4%CVE-2022-45306MEDIUMInsecure permissions in Chocolatey Azure-Pipelines-Agent package v2.211.1 and below grants all users in the Authenticated Users group write EPSS 0.4%CVE-2022-45301MEDIUMInsecure permissions in Chocolatey Ruby package v3.1.2.1 and below grants all users in the Authenticated Users group write privileges for thEPSS 0.4%CVE-2022-45304MEDIUMInsecure permissions in Chocolatey Cmder package v1.3.20 and below grants all users in the Authenticated Users group write privileges for thEPSS 0.4%CVE-2023-23939LOWAzure/setup-kubectl: Escalation of privilege vulnerability for v3 and lowerEPSS 0.4%CVE-2024-24740MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Application Server ABAP (SAP Kernel)EPSS 0.4%CVE-2025-0590HIGHImproper permission settings for mobile applications (com.transsion.carlcare) may lead to information leakage risk.EPSS 0.4%CVE-2024-41974HIGHWAGO: BACNet Service Property Modification Due to Permission Misconfiguration in Multiple DevicesEPSS 0.4%CVE-2024-37574HIGHThe GriceMobile com.grice.call application 4.5.2 for Android enables any installed application (with no permissions) to place phone calls wiEPSS 0.4%CVE-2025-45468HIGHInsecure permissions in fc-stable-diffusion-plus v1.0.18 allows attackers to escalate privileges and compromise the customer cloud account.EPSS 0.4%CVE-2026-24049HIGHwheel Allows Arbitrary File Permission Modification via Path TraversalEPSS 0.4%CVE-2020-7314HIGHPrivilege Escalation vulnerability in McAfee DXL for MacEPSS 0.4%CVE-2025-45472HIGHInsecure permissions in autodeploy-layer v1.2.0 allows attackers to escalate privileges and compromise the customer cloud account.EPSS 0.4%CVE-2024-53931CRITICALThe com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permEPSS 0.4%CVE-2024-53932CRITICALThe com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enableEPSS 0.4%