Fallos del tipo CWE-22

5964 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-24961MEDIUMInsecure path traversal in filesystem and filesystem-nio2 storage backends in org.gaul S3ProxyEPSS 0.5%CVE-2026-33027MEDIUMNginx UI: Improper Path Validation Allows Recursive Deletion of the Nginx Configuration DirectoryEPSS 0.5%CVE-2024-46954HIGHAn issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ..EPSS 0.5%CVE-2026-6320HIGHSalon Booking System – Free Version <= 10.30.25 - Unauthenticated Arbitrary File Read via Booking File Field Path TraversalEPSS 0.5%CVE-2026-40611HIGHLego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 ProviderEPSS 0.5%CVE-2026-82111MEDIUMiswalle getnote-mcp upload_image index.ts fs.readFileSync path traversalEPSS 0.5%CVE-2024-43797MEDIUMPath Traversal in audiobookshelfEPSS 0.5%CVE-2026-53940HIGHConda: Entry-point path traversal in noarch:python install (arbitrary file write) — canonical Python implementationEPSS 0.5%CVE-2026-7182CRITICALPath Traversal in DiagramEPSS 0.5%CVE-2026-74038HIGHWazuh 4.0.0 < 4.14.6 Path Traversal DoS via Agent EnrollmentEPSS 0.5%CVE-2026-67185HIGHTinyWeb 0.0.8 Path Traversal via URL Path ComponentEPSS 0.5%CVE-2025-27786HIGHApplio allows arbitrary file removal in core.pyEPSS 0.5%CVE-2025-4511MEDIUMvector4wang spring-boot-quick quick-img2txt Img2TxtController.java ResponseEntity path traversalEPSS 0.5%CVE-2025-51481MEDIUMLocal File Inclusion in dagster._grpc.impl.get_notebook_data in Dagster 1.10.14 allows attackers with access to the gRPC server to read arbiEPSS 0.5%CVE-2025-11002HIGH7-Zip ZIP File Parsing Directory Traversal Remote Code Execution VulnerabilityEPSS 0.5%CVE-2026-45774MEDIUMcompliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path TraversalEPSS 0.5%CVE-2023-47222CRITICALMedia Streaming add-onEPSS 0.5%CVE-2026-71493MEDIUMInfracost: Arbitrary file read via config-template readFile symlink traversalEPSS 0.5%CVE-2025-31827MEDIUMWordPress Fonto plugin <= 1.2.2 - Arbitrary File Download vulnerabilityEPSS 0.5%CVE-2026-100636HIGHSiYuan before v3.8.4 Path Traversal via exportBrowserHTML folderEPSS 0.5%