Fallos del tipo CWE-22

5902 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-45833MEDIUMWordPress Easy WP SMTP Plugin <= 1.5.1 is vulnerable to Directory TraversalEPSS 0.8%CVE-2022-36221MEDIUMNokia Fastmile 3tg00118abad52 is affected by an authenticated path traversal vulnerability which allows attackers to read any named pipe filEPSS 0.8%CVE-2026-87976HIGHApache NiFi Registry: Improper Limitation of Pathname in Persisted Extension BundlesEPSS 0.8%CVE-2026-66007MEDIUMDatasets Path Traversal via Unsanitized file_name MetadataEPSS 0.8%CVE-2023-36819MEDIUMKnowage-Server vulnerable to Path traversal in download functionalitiesEPSS 0.8%CVE-2023-46645MEDIUMPath traversal in GitHub Enterprise Server leading to arbitrary file reading when building a GitHub Pages siteEPSS 0.8%CVE-2024-45652MEDIUMIBM Maximo Asset Management directory traversalEPSS 0.8%CVE-2023-3031MEDIUMPrestahop module King-Avis - Path traversalEPSS 0.8%CVE-2026-73653CRITICALVitest: Browser Mode provider commands bypass the file-access permission gateEPSS 0.8%CVE-2025-27787HIGHApplio allows a DoS in restart.pyEPSS 0.8%CVE-2026-25965HIGHImageMagick's policy bypass through path traversal allows reading restricted content despite secured policyEPSS 0.8%CVE-2026-72567CRITICALdeepwiki-open - Unauthenticated Path Traversal Leading to Arbitrary File Write and DeleteEPSS 0.8%CVE-2026-20660MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in Safari 26.3, iOS 18.7.5 and iPadOS 18.7.5, iOS 26.3 and iPadEPSS 0.8%CVE-2026-14955MEDIUMCheckout Field Editor for WooCommerce (Pro) <= 3.7.7 - Authenticated (Subscriber+) Path Traversal to Arbitrary File Read via 'thwcfe_legacy_file' ParameterEPSS 0.8%CVE-2024-1433LOWKDE Plasma Workspace Theme File eventpluginsmanager.cpp enabledPlugins path traversalEPSS 0.8%CVE-2024-35428HIGHZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Directory Traversal via BaseMediaFile. An authenticated user can delete local files from the EPSS 0.8%CVE-2026-62391HIGHApache Kyuubi: kyuubi.session.local.dir.allow.list bypass via unprefixed Spark file-conf aliasesEPSS 0.8%CVE-2025-70084HIGHDirectory traversal vulnerability in OpenSatKit 2.2.1 allows attackers to gain access to sensitive information or delete arbitrary files viaEPSS 0.8%CVE-2024-1142MEDIUMSonatype IQ Server - Path TraversalEPSS 0.8%CVE-2025-6278MEDIUMUpsonic server.py os.path.join path traversalEPSS 0.8%