Fallos del tipo CWE-22

5890 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-27765MEDIUMDirectory Traversal vulnerability in Jeewms v.3.7 and before allows a remote attacker to obtain sensitive information via the cgformTemplateEPSS 0.9%CVE-2022-44016HIGHAn issue was discovered in Simmeth Lieferantenmanager before 5.6. An attacker can download arbitrary files from the web server by abusing anEPSS 0.9%CVE-2015-10024MEDIUMhoffie larasync file_storage.go path traversalEPSS 0.9%CVE-2025-3300HIGHWPMasterToolKit (WPMTK) – All in one plugin <= 2.5.2 - Authenticated (Administrator+) to Arbitrary File Read and WriteEPSS 0.9%CVE-2026-3289MEDIUMSanluan PublicCMS Template Cache Generation TemplateCacheComponent.java saveMetadata path traversalEPSS 0.9%CVE-2026-47429CRITICALVitest: Arbitrary file can be read and executed when Vitest UI server is listeningEPSS 0.9%CVE-2022-4636HIGHBlack Box KVM Firmware version 3.4.31307 on models ACR1000A-R-R2, ACR1000A-T-R2, ACR1002A-T, ACR1002A-R, and ACR1020A-T is vulnerable to patEPSS 0.9%CVE-2024-23904HIGHJenkins Log Command Plugin 1.0.2 and earlier does not disable a feature of its command parser that replaces an '@' character followed by a fEPSS 0.9%CVE-2021-43988MEDIUMICSA-22-109-03 FANUC ROBOGUIDE Simulation PlatformEPSS 0.9%CVE-2022-42136HIGHAuthenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had peEPSS 0.9%CVE-2024-3078MEDIUMQdrant Full Snapshot REST API snapshots.rs path traversalEPSS 0.9%CVE-2024-47464MEDIUMAuthenticated Path Traversal Vulnerability Leads to a Remote Unauthorized Access to FilesEPSS 0.9%CVE-2024-35474MEDIUMA Directory Traversal vulnerability in iceice666 ResourcePack Server before v1.0.8 allows a remote attacker to disclose files on the server,EPSS 0.9%CVE-2025-1770HIGHEvent Manager, Events Calendar, Tickets, Registrations – Eventin <= 4.0.24 - Authenticated (Contributor+) Local File InclusionEPSS 0.9%CVE-2024-24756HIGHCrafatar path traversal vulnerabilityEPSS 0.9%CVE-2014-125080MEDIUMfrontaccounting faplanet path traversalEPSS 0.9%CVE-2026-3405LOWthinkgem JeeSite Connection path traversalEPSS 0.9%CVE-2024-39406MEDIUMAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.9%CVE-2026-56623HIGHApache MINA SSHD: Path traversal in org.apache.sshd:sshd-git on WindowsEPSS 0.9%CVE-2026-35174CRITICALChyrp Lite has a Path Traversal to Remote Code ExecutionEPSS 0.9%