Fallos del tipo CWE-22

6055 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2021-36286HIGHDell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability thaEPSS 0.3%CVE-2026-40987HIGHRemote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalizationEPSS 0.3%CVE-2026-19722MEDIUMWPvivid Backup & Migration < 0.9.133 - Admin+ Arbitrary File Write via Zip Slip in Backup RestoreEPSS 0.3%CVE-2025-69620MEDIUMA path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.EPSS 0.3%CVE-2023-42947HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 aEPSS 0.3%CVE-2026-12568MEDIUMArbitrary File Write in postman_download moduleEPSS 0.3%CVE-2026-59839MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortEPSS 0.3%CVE-2023-24592HIGHPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentiallyEPSS 0.3%CVE-2025-43314MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, mEPSS 0.3%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2026-54561MEDIUMMCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePathEPSS 0.2%CVE-2025-43196HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2024-27827MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be abEPSS 0.2%CVE-2022-3560MEDIUMA flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script tEPSS 0.2%CVE-2024-44190MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7EPSS 0.2%CVE-2026-101126MEDIUMJoomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4EPSS 0.2%CVE-2026-3479NONEpkgutil.get_data() does not enforce documented restrictionsEPSS 0.2%CVE-2025-43191MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2025-3424HIGH3.2.1 Arbitrary File Read in insecure .NET Remoting TCP ChannelEPSS 0.2%CVE-2022-4123LOWA flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resultingEPSS 0.2%