Fallos del tipo CWE-22

5991 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-58386HIGHZoneMinder 1.37.x Path Traversal via files viewEPSS 0.4%CVE-2026-32193HIGHAzure Kubernetes Service (AKS) Remote Code Execution VulnerabilityEPSS 0.4%CVE-2026-49246LOWJellyfin: Potential MKV attachment filename path traversal to RCEEPSS 0.4%CVE-2026-49833MEDIUMDSpace: Path Traversal possible in LDN message generationEPSS 0.4%CVE-2026-48820MEDIUMCakePHP: View::element() is missing a path containment checkEPSS 0.4%CVE-2025-59414LOWNuxt Client-Side Path Traversal in Nuxt Island Payload RevivalEPSS 0.4%CVE-2026-102242HIGHPath Traversal via Symlink Following in allowedLocalRoots in MCP Toolbox for DatabasesEPSS 0.4%CVE-2026-48070HIGHDocmost: Avatar URL path traversal in avatar cleanup leads to arbitrary local file deletionEPSS 0.4%CVE-2025-69226MEDIUMAIOHTTP allows for a brute-force leak of internal static filepath componentsEPSS 0.4%CVE-2026-101126MEDIUMJoomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4EPSS 0.4%CVE-2024-21904MEDIUMQTS, QuTS heroEPSS 0.4%CVE-2024-3318MEDIUMSailPoint Identity Security Cloud Connector File Path Traversal VulnerabilityEPSS 0.4%CVE-2026-102424HIGHJoomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4EPSS 0.4%CVE-2025-29843MEDIUMA vulnerability in FileStation thumb cgi allows remote authenticated users to read/write image files.EPSS 0.4%CVE-2023-39957HIGHPath traversal allows tricking the Talk Android app into writing files into it's root directoryEPSS 0.4%CVE-2026-50558MEDIUMPenelope unsafe tar extraction allows arbitrary local file write via crafted session archiveEPSS 0.4%CVE-2025-71394LOWSurrealDB before 2.2.2 Local File Read via DEFINE ANALYZEREPSS 0.4%CVE-2026-18849MEDIUMIBM OpenBMC Code ExecutionEPSS 0.4%CVE-2026-34726MEDIUMCopier `_subdirectory` allows template root escape via parent-directory traversalEPSS 0.4%CVE-2026-39489MEDIUMWordPress Download Monitor plugin <= 5.1.9 - Non-Arbitrary File Download vulnerabilityEPSS 0.4%