Fallos del tipo CWE-22

6049 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-36597MEDIUMDell Avamar, versions prior to 19.12 with patch 338905, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path TraveEPSS 0.3%CVE-2026-48374HIGHBridge | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2025-10723LOWPixelYourSite < 11.1.2 - Admin+ LFIEPSS 0.3%CVE-2026-48441HIGHLightroom Classic | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2024-25859HIGHA path traversal vulnerability in the /path/to/uploads/ directory of Blesta before v5.9.2 allows attackers to takeover user accounts and exeEPSS 0.3%CVE-2026-105744HIGHDocling: Arbitrary file read/write (and command execution when shell-escape is enabled) when rendering untrusted TikZ with the opt-in Tectonic engineEPSS 0.3%CVE-2026-44437MEDIUMAngular SSR: Open Redirect and Request Steering via Encoded X-Forwarded-PrefixEPSS 0.3%CVE-2023-33544MEDIUMhawtio 2.17.2 is vulnerable to Path Traversal. it is possible to input malicious zip files, which can result in the high-risk files after deEPSS 0.3%CVE-2026-51570HIGHmodelscope Agentscope v1.0.0-v1.0.8 is vulnerable to Path Traversal in insert_text_file.EPSS 0.3%CVE-2026-49144HIGHBrowserStack Runner 0.9.5 Path Traversal via _default HTTP HandlerEPSS 0.3%CVE-2024-6618HIGHPath Traversal in Ocean Data Systems Dream ReportEPSS 0.3%CVE-2026-42080MEDIUMPPTAgent: Arbitrary File Write via `save_generated_slides`EPSS 0.3%CVE-2026-18133MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.3%CVE-2026-23485MEDIUMBlinko: Unauthorized Path Traversal File Enumeration - music-metadataEPSS 0.3%CVE-2025-8917MEDIUMPath Traversal Leading to Remote Code Execution in allegroai/clearmlEPSS 0.3%CVE-2026-42078MEDIUMPPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_imageEPSS 0.3%CVE-2026-79781MEDIUMrclone serve s3 Path Traversal via dot-dot object keysEPSS 0.3%CVE-2025-11020HIGHRemote Code Execution in MarkAny SafePC EnterpriseEPSS 0.3%CVE-2026-11470MEDIUMhs-web hsweb-framework File Upload FileUploadProperties.java denied path traversalEPSS 0.3%CVE-2024-42680MEDIUMAn issue in Super easy enterprise management system v.1.0.0 and before allows a local attacker to obtain the server absolute path by enterinEPSS 0.3%