Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-34657MEDIUMCAI Content Credentials | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 0.3%CVE-2026-106489MEDIUMBackstage: Improper authorization enforcement for TechDocs static contentEPSS 0.3%CVE-2025-48395MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%CVE-2025-27726LOWImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in the file download process of the USB storage EPSS 0.3%CVE-2026-91123HIGHDiscourse: Reject literal backslash path separators in iframe src traversal guardEPSS 0.3%CVE-2022-2464HIGHISaGRAF Workbench Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-22EPSS 0.3%CVE-2025-48394MEDIUMAn attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limitedEPSS 0.3%CVE-2026-10601MEDIUMPath traversal in the Tempo and Loki data source pluginsEPSS 0.3%CVE-2026-73973MEDIUMLinuxfabrik Monitoring Plugins: Arbitrary root file disclosure via unconfined --filename in logfile plugin (sudoers LPE)EPSS 0.3%CVE-2026-106494MEDIUMBackstage: Improper input validation in cloud storage URL readersEPSS 0.3%CVE-2026-75104MEDIUMHugging Face Transformers Path Traversal via Checkpoint IndexEPSS 0.3%CVE-2023-47541MEDIUMAn improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2EPSS 0.3%CVE-2021-33183HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability container volume management component in SynoloEPSS 0.3%CVE-2023-44278MEDIUM Dell PowerProtect DD , versions prior to 7.13.0.10, LTS 7.7.5.25, LTS 7.10.1.15, 6.2.1.110 contain a path traversal vulnerability. A localEPSS 0.3%CVE-2026-7766HIGHPath Traversal in Kenik camerasEPSS 0.3%CVE-2024-1630HIGHPath traversal vulnerability in “getAllFolderContents” function of Common Service Desktop, a GE HealthCare ultrasound device componentEPSS 0.3%CVE-2024-34129HIGHAcrobat Android : OverSecured Finding : Overwriting arbitrary files via attacker-controlled output file pathsEPSS 0.3%CVE-2026-106508MEDIUMBackstage: Potential file exposure through local TechDocs publisherEPSS 0.3%CVE-2024-1629MEDIUMPath traversal vulnerability in “deleteFiles” function of Common Service Desktop, a GE HealthCare ultrasound device componentEPSS 0.3%CVE-2023-35946MEDIUMDependency cache path traversal in GradleEPSS 0.3%