Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-8464HIGHPath traversal in Neuron Soft Golem OEE MESEPSS 0.3%CVE-2026-90925HIGHPath Traversal in Innotim Software's Logsign SIEMEPSS 0.3%CVE-2025-11221CRITICALRemote Code Execution in GTONE ChangeFlowEPSS 0.3%CVE-2023-52953MEDIUMPath traversal vulnerability in the Medialibrary module Impact: Successful exploitation of this vulnerability will affect integrity and confEPSS 0.3%CVE-2024-2602HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could result in remote codeEPSS 0.3%CVE-2024-45601HIGHLocal file Inclusion via static file serving functionality in MesopEPSS 0.3%CVE-2026-103254HIGHn8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL GenerationEPSS 0.3%CVE-2026-19693HIGHextract-zip arbitrary file write outside the destination directory via a symlink at the final path componentEPSS 0.3%CVE-2023-52623HIGHSUNRPC: Fix a suspicious RCU usage warningEPSS 0.3%CVE-2025-24330MEDIUMOAM service path traversal issue caused by a crafted SOAP message PlanId field within the RAN management networkEPSS 0.3%CVE-2025-22479LOWDell Storage Center - Dell Storage Manager, version(s) 20.0.21, contain(s) an Improper Limitation of a Pathname to a Restricted Directory ('EPSS 0.3%CVE-2025-42894MEDIUMPath Traversal vulnerability in SAP Business ConnectorEPSS 0.3%CVE-2026-24131MEDIUMpnpm has Path Traversal via arbitrary file permission modificationEPSS 0.3%CVE-2026-18515MEDIUMIBM i is Affected By Multiple Vulnerabilities in Navigator for i and Digital Certificate Manager for i.EPSS 0.3%CVE-2026-92945LOWvm2 before 3.11.7 Module Allowlist Bypass via Prefix MatchingEPSS 0.3%CVE-2024-47273MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology HypEPSS 0.3%CVE-2025-54559LOWAn issue was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2 which allows remote Path Traversal for lEPSS 0.3%CVE-2026-20613HIGHThe ArchiveReader.extractContents() function used by cctl image load and container image load performs no pathname validation before extractEPSS 0.3%CVE-2026-100549MEDIUMOpenClaw before 2026.8.1 Path Traversal via QQBot voice filenamesEPSS 0.3%CVE-2026-19016MEDIUMAuthorization bypass for session deletion in the transaction APIEPSS 0.3%