Fallos del tipo CWE-22

5913 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-7098MEDIUMComodo Internet Security Premium File Name path traversalEPSS 0.7%CVE-2026-82428HIGHApache Storm Client: Cross-Tenant Dependency Jar Substitution via Predictable Blob KeysEPSS 0.7%CVE-2024-22231MEDIUMSyndic cache directory creation is vulnerable to a directory traversal attackEPSS 0.7%CVE-2025-14301CRITICALIntegration Opvius AI for WooCommerce <= 1.3.0 - Unauthenticated Arbitrary File Deletion/Read via Path TraversalEPSS 0.7%CVE-2025-39664HIGHPath-Traversal in report schedulerEPSS 0.7%CVE-2026-25891HIGHFiber has an Arbitrary File Read in Static Middleware on WindowsEPSS 0.7%CVE-2024-55602HIGHPenDoc vulnerable to Arbitrary File Read on updating and downloading templates using Path TraversalEPSS 0.7%CVE-2024-9301HIGHA path traversal issue in E2Nest prior to commit 8a41948e553c89c56b14410c6ed395e9cfb9250aEPSS 0.7%CVE-2025-27937HIGHQuick Agent V3 and Quick Agent V2 contain an issue with improper limitation of a pathname to a restricted directory ('Path Traversal'). If eEPSS 0.7%CVE-2024-8410MEDIUMABCD ABCD2 otros_sitios.php path traversalEPSS 0.7%CVE-2026-36762HIGHAn issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload perEPSS 0.7%CVE-2025-57682MEDIUMDirectory Traversal vulnerability in Papermark 0.20.0 and prior allows authenticated attackers to retrieve arbitrary files from an S3 bucketEPSS 0.7%CVE-2023-37218HIGH Tadiran Telecom Aeonix - CWE-22: Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.7%CVE-2026-7396MEDIUMNousResearch hermes-agent WeChat Work Platform Adapter wecom.py path traversalEPSS 0.7%CVE-2026-19827MEDIUMalldatacenter alldata logDetailCat Endpoint JobLogController.java FileInputStream path traversalEPSS 0.7%CVE-2026-81485MEDIUMdanielpopamd linkedin-ads-mcp Media Upload campaign-management.ts fs.readFileSync path traversalEPSS 0.7%CVE-2026-7271MEDIUMDV0x creative-ad-agent creative-ad-agent-server sdk-server.ts path traversalEPSS 0.7%CVE-2026-81486MEDIUMbsmi021 mcp-file-context-server Path Resolution index.ts read_context path traversalEPSS 0.7%CVE-2026-5638MEDIUMHerikLyma CPPWebFramework path traversalEPSS 0.7%CVE-2026-16653MEDIUMboazsegev facil.io Public Folder http.c http_sendfile2 path traversalEPSS 0.7%