Fallos del tipo CWE-22

6040 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-24268MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.4. AEPSS 0.1%CVE-2022-20505MEDIUMIn openFile of CallLogProvider.java, there is a possible permission bypass due to a path traversal error. This could lead to local escalatioEPSS 0.1%CVE-2026-101080LOWTencent AI-Infra-Guard File Access dir_actions.py startsWith path traversalEPSS 0.1%CVE-2026-20669MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Tahoe 26.3. An EPSS 0.1%CVE-2025-11565HIGHCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause elevated systemEPSS 0.1%CVE-2026-22926HIGHOmnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.EPSS 0.1%CVE-2026-0055MEDIUMIn createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid dirEPSS 0.1%CVE-2026-41009MEDIUMLocal Blobstore may allow arbitrary reads/deletesEPSS 0.1%CVE-2026-19743HIGHImproper Limitation of a Pathname to a Restricted Directory (Path Traversal) in TeamViewer Desktop ClientsEPSS 0.1%CVE-2026-57966MEDIUMSpice-vdagent: path traversal in file transfer via unsanitized filenameEPSS 0.1%CVE-2026-106109MEDIUMQuasar Framework: App Vite build cleanup can recursively remove unsafe configured output directoriesEPSS 0.1%CVE-2026-3223HIGHZip Slip leading to Arbitrary File Write and Privilege Escalation in Google Web DesignerEPSS 0.1%CVE-2025-54652HIGHPath traversal vulnerability in the virtualization base module. Successful exploitation of this vulnerability may affect the confidentialityEPSS 0.1%CVE-2022-28784MEDIUMPath traversal vulnerability in Galaxy Themes prior to SMR May-2022 Release 1 allows attackers to list file names in arbitrary directory as EPSS 0.1%CVE-2025-54653HIGHPath traversal vulnerability in the virtualization file module. Successful exploitation of this vulnerability may affect the confidentialityEPSS 0.1%CVE-2025-53594MEDIUMQfinder Pro, Qsync, QVPNEPSS 0.1%CVE-2026-53766MEDIUMchrome-devtools-mcp: validatePath() does not canonicalize symlinks before enforcing rootsEPSS 0.1%CVE-2021-25452MEDIUMAn improper input validation vulnerability in loading graph file in DSP driver prior to SMR Sep-2021 Release 1 allows attackers to perform pEPSS 0.1%CVE-2026-15953MEDIUMPath Traversal During Project Archive ImportEPSS 0.1%CVE-2025-48567HIGHIn multiple locations, there is a possible bypass of a file path filter designed to prevent access to sensitive directories due to incorrecEPSS 0.1%