Weaknesses of type CWE-732

785 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2025-1731HIGHAn incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 EPSS 0.9%CVE-2021-32526MEDIUMQSAN Storage Manager - Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2019-3683HIGHkeystone_json_assignment backend granted access to any project for users in user-project-map.jsonEPSS 0.9%CVE-2021-40331HIGHPermissions problem in the Apache Ranger Hive PluginEPSS 0.9%CVE-2021-38475HIGHAUVESY VersiondogEPSS 0.9%CVE-2021-22648HIGHOvarro TBox Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2021-35248MEDIUMUnrestricted access to Orion.UserSettings SWIS entity for low-privilege usersEPSS 0.9%CVE-2023-28346HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API EPSS 0.9%CVE-2022-48257MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.EPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2017-8450X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a doEPSS 0.9%CVE-2025-21581MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-21584MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.9%CVE-2025-30685MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-30683MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-21585MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-30684MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2022-35250MEDIUMA privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to viEPSS 0.9%CVE-2025-21583MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0EPSS 0.8%