Fallos del tipo CWE-22

5908 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-34345MEDIUMAMI BMC contains a vulnerability in the SPX REST API, where an attacker with the required privileges can access arbitrary files, which may lEPSS 0.7%CVE-2026-34745CRITICALUnauthenticated Path Traversal Arbitrary File Write in /api/uploadChunked/publicEPSS 0.7%CVE-2026-42882CRITICALoxyno-zeta/s3-proxy: Security Issues in Resource Path MatchingEPSS 0.7%CVE-2026-6615MEDIUMTransformerOptimus SuperAGI Multipart Upload resources.py upload path traversalEPSS 0.7%CVE-2026-9550MEDIUMAcrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform upfile path traversalEPSS 0.7%CVE-2026-44522HIGHNote Mark: Arbitrary File Write via Path Traversal in Asset Names Leading to Remote Code ExecutionEPSS 0.7%CVE-2023-52289HIGHAn issue was discovered in the flaskcode package through 0.0.8 for Python. An unauthenticated directory traversal, exploitable with a POST rEPSS 0.7%CVE-2026-6568MEDIUMkodcloud KodExplorer Public Share share.class.php initShareOld path traversalEPSS 0.7%CVE-2026-8756MEDIUMfishaudio Bert-VITS2 Gradio webui_preprocess.py generate_config path traversalEPSS 0.7%CVE-2026-5258MEDIUMSanster IOPaint File Manager file_manager.py _get_file path traversalEPSS 0.7%CVE-2026-8755MEDIUMfishaudio Bert-VITS2 Model hiyoriUI.py _get_all_models path traversalEPSS 0.7%CVE-2026-95698MEDIUMMISP Path Traversal in OrgImgHelper findOrgImage via Crafted Organization NameEPSS 0.7%CVE-2025-11630MEDIUMRainyGao DocSys File Upload uploadDoc.do updateRealDoc path traversalEPSS 0.7%CVE-2024-10830HIGHPath Traversal in eosphoros-ai/db-gptEPSS 0.7%CVE-2022-46178HIGHPath Traversal In MeterSpere allows file upload to any pathEPSS 0.7%CVE-2022-34762MEDIUMA CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized EPSS 0.7%CVE-2026-77914HIGHrConfig Core 8.0.0 < 8.2.13 Core Path Traversal via Export Download EndpointEPSS 0.7%CVE-2026-66897CRITICALInstance template path traversal allows arbitrary host file write as rootEPSS 0.7%CVE-2023-38256MEDIUMDover Fueling Solutions MAGLINK LX Console Path TraversalEPSS 0.7%CVE-2025-1310MEDIUMJobs for WordPress <= 2.7.11 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.7%