Fallos del tipo CWE-22

6051 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-59825MEDIUMastral-tokio-tar has a path traversal in tar extractionEPSS 0.2%CVE-2023-21456CRITICALPath traversal vulnerability in Galaxy Themes Service prior to SMR Mar-2023 Release 1 allows attacker to access arbitrary file with system uEPSS 0.2%CVE-2026-20625MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.4,EPSS 0.2%CVE-2026-104805HIGHMitel MiVoice Office 400 Backup Restoration Arbitrary File Write Leading to Root Code ExecutionEPSS 0.2%CVE-2026-41433HIGHOpenTelemetry eBPF Instrumentation: Privileged Java agent injection allows arbitrary host file overwrite via untrusted TMPDIREPSS 0.2%CVE-2025-14311MEDIUMImproper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in JMRI.This issue affects JMRI: before 5.13.3.EPSS 0.2%CVE-2025-43417MEDIUMA path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe 26.2.EPSS 0.2%CVE-2025-43463MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.3,EPSS 0.2%CVE-2026-30279HIGHAn arbitrary file overwrite vulnerability in Squareapps LLC My Location Travel Timeline v11.80 allows attackers to overwrite critical internEPSS 0.2%CVE-2026-30277HIGHAn arbitrary file overwrite vulnerability in PDF Reader App : TA/UTAX Mobile Print v3.7.2.251001 allows attackers to overwrite critical inteEPSS 0.2%CVE-2025-54658HIGHAn Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's OutlooEPSS 0.2%CVE-2026-82708HIGHBotslab G980H Dashcams Improper Limitation of a Pathname to a Restricted DirectoryEPSS 0.2%CVE-2024-7061MEDIUMOkta Verify for Windows is vulnerable to privilege escalation through DLL hijacking. The vulnerability is fixed in Okta Verify for Windows vEPSS 0.2%CVE-2026-28793HIGHPath Traversal Leading to Arbitrary File Read, Write and Delete in TinaCMSEPSS 0.2%CVE-2023-31427HIGHKnowledge of full path nameEPSS 0.2%CVE-2026-103884MEDIUMKeycloak-services: keycloak-services: path traversal in x.509 crl distribution point allows arbitrary local file readEPSS 0.2%CVE-2026-41861MEDIUMArbitrary Root File Write via Path Traversal in BOSH agentEPSS 0.2%CVE-2026-26972MEDIUMOpenClaw has a Path Traversal in Browser Download FunctionalityEPSS 0.2%CVE-2026-19059MEDIUMFoundationAgents MetaGPT editor.py read path traversalEPSS 0.2%CVE-2026-28827CRITICALA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5,EPSS 0.2%