Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2026-20685MEDIUMAn attacker in a privileged network position may be able to leak sensitive information. A path handling issue was addressed with improved vaEPSS 0.3%CVE-2025-0694MEDIUMCODESYS Control V3 removable media path traversalEPSS 0.3%CVE-2026-20688CRITICALA path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS SEPSS 0.3%CVE-2026-19438HIGHMint Workbench I Path traversal VulnerabilityEPSS 0.3%CVE-2026-17424MEDIUMVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.3%CVE-2024-50559MEDIUMA vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2) (All versions < V8.2), RUGGEDCOM RM1224 LTE(4G) NAM EPSS 0.3%CVE-2023-2270HIGHLocal privilege escalationEPSS 0.3%CVE-2024-23216MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.4, macOS Sonoma 14.4, macOS VenturaEPSS 0.3%CVE-2025-61646LOWWatchlist group mode reveals authors of edits with hidden authorshipEPSS 0.3%CVE-2025-10559HIGHPath Traversal vulnerability affecting Factory Resource Management in DELMIA Factory Resource Manager from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2025xEPSS 0.3%CVE-2025-61658LOWSpecial:GlobalContributions shows edits on wikis the viewer doesn't have access toEPSS 0.3%CVE-2025-43190MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in iOS 26 and iPadOS 26,EPSS 0.3%CVE-2025-8941HIGHLinux-pam: incomplete fix for cve-2025-6020EPSS 0.3%CVE-2024-10933MEDIUMOpenBSD readdir directory traversalEPSS 0.3%CVE-2025-53905MEDIUMVim has path traversial issue with tar.vim and special crafted tar filesEPSS 0.3%CVE-2026-106491MEDIUMBackstage: Improper input validation in proxy-backendEPSS 0.3%CVE-2023-4782MEDIUMTerraform Allows Arbitrary File Write During Init OperationEPSS 0.3%CVE-2025-24329MEDIUMOAM service path traversal issue caused by a crafted SOAP message archive field within the RAN management networkEPSS 0.3%CVE-2017-20181MEDIUMhgzojer Vocable Trainer VocableTrainerProvider.java path traversalEPSS 0.3%CVE-2026-10264MEDIUMlharries whatsapp-mcp Send API Endpoint main.go SendMessageRequest path traversalEPSS 0.3%