Fallos del tipo CWE-22

6044 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-11696HIGHStudio 5000 ® Simulation Interface SSRFEPSS 0.2%CVE-2024-37129MEDIUMDell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potEPSS 0.2%CVE-2026-41124LOWDell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.2%CVE-2026-20614HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.4, macOS Sonoma 14.8.4, macOS Tahoe EPSS 0.2%CVE-2025-43934MEDIUMDell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.3.0.15, LTS2025 releasEPSS 0.2%CVE-2026-86886MEDIUMA path traversal issue was addressed with improved input validation. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, EPSS 0.2%CVE-2026-73974MEDIUMlinuxfabrik-lib: Arbitrary root file read via live --test argument (lib.lftest) across sudoers-whitelisted plugins (LPE)EPSS 0.2%CVE-2025-20277LOWCisco Unified Contact Center Express Path Traversal VulnerabilityEPSS 0.2%CVE-2025-31248MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.5, mEPSS 0.2%CVE-2026-54250MEDIUMK3s: ZIP Archive Path Traversal Vulnerability in etcd Snapshot DecompressionEPSS 0.2%CVE-2026-102875HIGHVLC media player before 3.0.24 Path Traversal via skins2EPSS 0.2%CVE-2021-25361HIGHAn improper access control vulnerability in stickerCenter prior to SMR APR-2021 Release 1 allows local attackers to read or write arbitrary EPSS 0.2%CVE-2016-20048HIGHiSelect 1.4.0-2+b1 Local Buffer Overflow via key parameterEPSS 0.2%CVE-2026-101036MEDIUMFLB-Music FLB-Music-Player createParsedTrack.ts path.join path traversalEPSS 0.2%CVE-2026-20615HIGHA path handling issue was addressed with improved validation. This issue is fixed in iOS 26.3 and iPadOS 26.3, macOS Sequoia 15.7.4, macOS SEPSS 0.2%CVE-2026-33922MEDIUMPath traversal in the Offline archives functionality of the local web interface in Arc before v2.7.0EPSS 0.2%CVE-2025-0542HIGHG DATA Management Server Local privilege escalationEPSS 0.2%CVE-2022-20453MEDIUMIn update of MmsProvider.java, there is a possible constriction of directory permissions due to a path traversal error. This could lead to lEPSS 0.2%CVE-2026-8069HIGHPredatorSense V3: Local Privilege Escalation (LPE) vulnerabilityEPSS 0.2%CVE-2025-14617MEDIUMJehovahs Witnesses JW Library App org.jw.jwlibrary.mobile.activity.SiloContainer path traversalEPSS 0.2%