Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2025-69411HIGHWordPress ionCube tester plus plugin <= 1.3 - Arbitrary File Download vulnerabilityEPSS 1.6%CVE-2022-25882HIGHVersions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a pEPSS 1.6%CVE-2014-10066—Versions less than 0.1.4 of the static file server module fancy-server are vulnerable to directory traversal. An attacker can provide input EPSS 1.6%CVE-2021-21357HIGHBroken Access Control in Form FrameworkEPSS 1.6%CVE-2025-0572MEDIUMSante PACS Server Web Portal DCM File Parsing Directory Traversal Arbitrary File Write VulnerabilityEPSS 1.6%CVE-2019-5480—A path traversal vulnerability in <= v0.9.7 of statichttpserver npm module allows attackers to list files in arbitrary folders.EPSS 1.6%CVE-2021-29474MEDIUMRelative Path Traversal Attack on note creationEPSS 1.6%CVE-2024-11944HIGHiXsystems TrueNAS CORE tarfile.extractall Directory Traversal Remote Code Execution VulnerabilityEPSS 1.6%CVE-2026-5492MEDIUMDriveLock Directory Traversal Information Disclosure VulnerabilityEPSS 1.6%CVE-2022-34426HIGHDell Container Storage Modules 1.2 contains an Improper Limitation of a Pathname to a Restricted Directory in goiscsi and gobrick libraries EPSS 1.6%CVE-2018-1048—It was found that the AJP connector in undertow, as shipped in Jboss EAP 7.1.0.GA, does not use the ALLOW_ENCODED_SLASH option and thus alloEPSS 1.6%CVE-2023-36534CRITICALPath traversal in Zoom Desktop Client for Windows before 5.14.7 may allow an unauthenticated user to enable an escalation of privilege via nEPSS 1.6%CVE-2021-32674HIGHRemote Code Execution via traversal in TAL expressionsEPSS 1.6%CVE-2025-23084MEDIUMA vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.EPSS 1.6%CVE-2022-26884MEDIUMApache DolphinScheduler exposes files without authenticationEPSS 1.6%CVE-2021-41281HIGHPath traversal in Matrix SynapseEPSS 1.6%CVE-2025-55169CRITICALWeGIA Path Traversal at endpoint 'html/socio/sistema/download_remessa.php' via parameter 'file'EPSS 1.6%CVE-2022-29474MEDIUMOn F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior EPSS 1.6%CVE-2023-51599HIGHHoneywell Saia PG5 Controls Suite Directory Traversal Remote Code Execution VulnerabilityEPSS 1.6%CVE-2025-34023HIGHKarel IP Phone IP1211 Path TraversalEPSS 1.6%