Fallos del tipo CWE-22

5906 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-81377MEDIUMVisual Studio Code Tampering VulnerabilityEPSS 0.8%CVE-2025-8021HIGHAll versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and accEPSS 0.8%CVE-2026-62801MEDIUMMicrosoft PowerShell Security Feature Bypass VulnerabilityEPSS 0.8%CVE-2026-53457MEDIUMBlueprint Studio terminal command working directory not bounded to config directoryEPSS 0.8%CVE-2024-24749HIGHClasspath resource disclosure in GWC Web Resource API on Windows / TomcatEPSS 0.8%CVE-2023-42226HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via Email/SaveAttachment function.EPSS 0.8%CVE-2023-42227HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the WSCView/Save function.EPSS 0.8%CVE-2022-42125HIGHZip slip vulnerability in FileUtil.unzip in Liferay Portal 7.4.3.5 through 7.4.3.35 and Liferay DXP 7.4 update 1 through update 34 allows atEPSS 0.8%CVE-2022-4402MEDIUMRainyGao DocSys ZIP File Decompression path traversalEPSS 0.8%CVE-2023-42225HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Directory Traversal via the Attachment/DownloadTempFile function.EPSS 0.8%CVE-2022-42123HIGHA Zip slip vulnerability in the Elasticsearch Connector in Liferay Portal 7.3.3 through 7.4.3.18, and Liferay DXP 7.3 before update 6, and 7EPSS 0.8%CVE-2023-39528MEDIUMPrestaShop vulnerable to file reading through path traversalEPSS 0.8%CVE-2023-6908LOWDFIRKuiper TAR Archive case_management.py unzip_file path traversalEPSS 0.8%CVE-2022-47595MEDIUMWordPress WP Google Maps Plugin <= 9.0.15 is vulnerable to Path TraversalEPSS 0.8%CVE-2025-5740HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file EPSS 0.8%CVE-2026-28208MEDIUMJunrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/UnixEPSS 0.8%CVE-2025-3671HIGHWPGYM - Wordpress Gym Management System <= 67.7.0 - Authenticated (Subscriber+) Local File Inclusion to Privilege Escalation via Password UpdateEPSS 0.8%CVE-2023-38366MEDIUMIBM FileNet Content Manager directory traversalEPSS 0.8%CVE-2025-5014HIGHHome Villas | Real Estate WordPress Theme <= 2.8 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.8%CVE-2025-2932HIGHJKDEVKIT <= 1.9.4 - Authenticated (Subscriber+) Arbitrary File DeletionEPSS 0.8%