Fallos del tipo CWE-22

6048 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-15789MEDIUMMalicious client can bypass destination directory validation on local sources uploadEPSS 0.3%CVE-2024-9597HIGHPath Traversal in parisneo/lollmsEPSS 0.3%CVE-2026-51862CRITICALDB-GPT 0.8.0 contains directory traversal in skill_upload (packages/dbgpt-app/src/dbgpt_app/openapi/api_v1/agentic_data_api.py:40). A remoteEPSS 0.3%CVE-2026-82094HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.3%CVE-2025-49089MEDIUMwangxutech MoneyPrinterTurbo 1.2.6 allows path traversal via /api/v1/download/ URIs such as /api/v1/download//etc/passwd.EPSS 0.3%CVE-2026-105840HIGHlrzsz before 0.13.0 Path Traversal via lrz Restricted Mode checkpath()EPSS 0.3%CVE-2026-6903HIGHPath Traversal Vulnerability in LabOne User InterfaceEPSS 0.3%CVE-2021-1436MEDIUMCisco IOS XE SD-WAN Software Path Traversal VulnerabilityEPSS 0.3%CVE-2026-97164HIGHJoomla Extension - svenbluege.de - Path Traversal in Clear Cache task in Event Gallery extension < 6.5.0EPSS 0.3%CVE-2023-41973HIGHLack of input santization on Zscaler Client Connector enables arbitrary code executionEPSS 0.3%CVE-2022-40264MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versioEPSS 0.3%CVE-2022-39210LOWAccess to internal files of the Nextcloud Android appEPSS 0.3%CVE-2020-25243MEDIUMA vulnerability has been identified in LOGO! Soft Comfort (All versions < V8.4). A zip slip vulnerability could be triggered while importingEPSS 0.3%CVE-2025-6210MEDIUMHardlink-Based Path Traversal in run-llama/llama_indexEPSS 0.3%CVE-2026-14505MEDIUMTanium addressed a path traversal vulnerability in Tanium Data Service.EPSS 0.3%CVE-2024-44255HIGHA path handling issue was addressed with improved logic. This issue is fixed in iOS 18.1 and iPadOS 18.1, macOS Sequoia 15.1, macOS Sonoma 1EPSS 0.3%CVE-2026-105125MEDIUMLaraDashboard before 1.4.8 Path Traversal via /api/translations/{lang} EndpointEPSS 0.3%CVE-2021-3960HIGHPrivilege Escalation via the GravityZone productManager UpdateServer.KitsManager API (VA-10146)EPSS 0.3%CVE-2025-14965MEDIUM1541492390c yougou-mall ResourceController.java delete path traversalEPSS 0.3%CVE-2026-86105MEDIUMFireware OS Improper Authorization in Access Portal Reverse ProxyEPSS 0.3%