Weaknesses of type CWE-732

785 results

Permissões inadequadas em recursos críticos de segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos, credenciais, configurações críticas ou dados pessoais a quem não deveria ter acesso.

Example

Um arquivo de configuração contendo chaves de API é criado com permissões 644 (legível por qualquer usuário do sistema) ao invés de 600 (apenas o proprietário). Um atacante local lê a chave e compromete a aplicação na nuvem. Ou um diretório temporário armazena tokens de sessão com permissões 777, permitindo que outros processos roubem sessões ativas.

How to mitigate

Aplique o princípio do menor privilégio: configure permissões restritivas no momento da criação (ex: 600 para arquivos sensíveis, 700 para diretórios). Use umask apropriado, revise periodicamente as permissões de recursos críticos e automatize verificações de compliance com ferramentas como Terraform ou Ansible para manter a postura correta.

CVE-2025-21580MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.7%CVE-2025-21579MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.EPSS 0.7%CVE-2023-0225MEDIUMA flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this atEPSS 0.7%CVE-2022-40756HIGHIf folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01EPSS 0.7%CVE-2023-35168MEDIUMDataEase has a privilege bypass vulnerabilityEPSS 0.7%CVE-2022-4365MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 beforeEPSS 0.7%CVE-2024-37087MEDIUMThe vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-oEPSS 0.7%CVE-2022-43946HIGHMultiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check timeEPSS 0.7%CVE-2024-41647CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2025-21566MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 anEPSS 0.7%CVE-2022-40298HIGHCrestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found EPSS 0.7%CVE-2022-46338MEDIUMg810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable anEPSS 0.7%CVE-2023-22294HIGHPrivilege escalation in Checkmk ApplianceEPSS 0.7%CVE-2022-36103HIGHTalos worker join token can be used to get elevated access level to the Talos APIEPSS 0.7%CVE-2024-44729HIGHIncorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenEPSS 0.7%CVE-2024-12564MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in ODA CDE inWEB SDK before 2025.3EPSS 0.7%CVE-2025-30708HIGHVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions tEPSS 0.7%CVE-2025-34212HIGHVasion Print (formerly PrinterLogic) Insecure Build PipelineEPSS 0.7%CVE-2024-24117CRITICALInsecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via tEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%