Weaknesses of type CWE-732

785 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2017-20198CRITICALDC/OS Marathon UI < 1.9.0 Unauthenticated RCE via Docker Mount AbuseEPSS 1.1%CVE-2020-25191Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a functiEPSS 1.1%CVE-2022-0277MEDIUMIncorrect Permission Assignment for Critical Resource in microweber/microweberEPSS 1.1%CVE-2023-34981HIGHApache Tomcat: AJP response header mix-upEPSS 1.1%CVE-2025-6779MEDIUMAn ACAP configuration file has improper permissions, which could allow command injection and potentially lead to privilege escalation. This EPSS 1.1%CVE-2022-24872HIGHImproper Access Control in shopwareEPSS 1.1%CVE-2021-25318HIGHrancher: API group not properly specified when creating Kubernetes RBAC resourcesEPSS 1.1%CVE-2023-34852PublicCMS <=V4.0.202302 is vulnerable to Insecure Permissions.EPSS 1.0%CVE-2024-57520CRITICALInsecure Permissions vulnerability in asterisk v22 allows a remote attacker to execute arbitrary code via the action_createconfig function. EPSS 1.0%CVE-2021-22147Elasticsearch before 7.14.0 did not apply document and field level security to searchable snapshots. This could lead to an authenticated useEPSS 1.0%CVE-2023-47564HIGHQsync CentralEPSS 1.0%CVE-2021-22850MEDIUMHGiga OAKloud Portal - Security MisconfigurationEPSS 1.0%CVE-2024-21915CRITICALRockwell Automation FactoryTalk® Service Platform Elevated Privileges Vulnerability Through Web Service FunctionalityEPSS 1.0%CVE-2020-5417HIGHCloud Controller may allow developers to claim sensitive routesEPSS 1.0%CVE-2026-25770CRITICALWazuh has Privilege Escalation to Root via Cluster Protocol File WriteEPSS 1.0%CVE-2021-22148Elastic Enterprise Search App Search versions before 7.14.0 was vulnerable to an issue where API keys were not bound to the same engines as EPSS 1.0%CVE-2021-22149Elastic Enterprise Search App Search versions before 7.14.0 are vulnerable to an issue where API keys were missing authorization via an alteEPSS 1.0%CVE-2025-21523MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8EPSS 1.0%CVE-2024-33435CRITICALInsecure Permissions vulnerability in Guangzhou Yingshi Electronic Technology Co. Ncast Yingshi high-definition intelligent recording and plEPSS 0.9%CVE-2023-30399HIGHInsecure permissions in the settings page of GARO Wallbox GLB/GTB/GTC before v189 allows attackers to redirect users to a crafted update pacEPSS 0.9%