Weaknesses of type CWE-732

791 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2025-34135MEDIUMNagios XI < 2024R1.4.2 Overly Permissive Permissions on Systemd Unit FilesEPSS 0.3%CVE-2024-47104MEDIUMIBM i incorrect privilege assignmentEPSS 0.3%CVE-2024-2905MEDIUMRpm-ostree: world-readable /etc/shadow fileEPSS 0.3%CVE-2019-19335MEDIUMDuring installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and EPSS 0.3%CVE-2025-34323HIGHNagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo RulesEPSS 0.3%CVE-2022-32929MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.EPSS 0.3%CVE-2023-49797HIGHLocal Privilege Escalation in pyinstaller on WindowsEPSS 0.3%CVE-2023-31142LOWDiscourse's general category permissions could be set back to defaultEPSS 0.3%CVE-2023-49257HIGHCommand execution using the certificate upload utilityEPSS 0.3%CVE-2025-12004CRITICALThe compare API module breaks Extension:LockdownEPSS 0.3%CVE-2024-45164MEDIUMAkamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch anEPSS 0.3%CVE-2024-39967MEDIUMInsecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.EPSS 0.3%CVE-2019-19341MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files inclEPSS 0.3%CVE-2025-52873HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2025-54497HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2020-10781MEDIUMA flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read theEPSS 0.3%CVE-2019-5642LOWMAGICKEPSS 0.3%CVE-2024-41954MEDIUMFOG Weak file permissionsEPSS 0.3%CVE-2025-0093HIGHIn handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lEPSS 0.3%CVE-2016-8637MEDIUMA local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'eEPSS 0.3%