Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2023-38346HIGHAn issue was discovered in Wind River VxWorks 6.9 and 7. The function ``tarExtract`` implements TAR file extraction and thereby also processEPSS 1.5%CVE-2025-47273HIGHsetuptools has a path traversal vulnerability in PackageIndex.download that leads to Arbitrary File WriteEPSS 1.5%CVE-2023-46253CRITICALRemote code execution in SquidexEPSS 1.5%CVE-2020-15124CRITICALPath traversal in Goobi viewer CoreEPSS 1.5%CVE-2024-49082MEDIUMWindows File Explorer Information Disclosure VulnerabilityEPSS 1.5%CVE-2021-37317CRITICALDirectory Traversal vulnerability in Cloud Disk in ASUS RT-AC68U router firmware version before 3.0.0.4.386.41634 allows remote attackers toEPSS 1.5%CVE-2024-27081HIGHESPHome remote code execution via arbitrary file writeEPSS 1.5%CVE-2025-4206HIGHWordPress CRM, Email & Marketing Automation for WordPress | Award Winner — Groundhogg <= 4.1.1.2 - Authenticated (Administrator+) Arbitrary File DeletionEPSS 1.5%CVE-2010-0481MEDIUMThe kernel in Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properly translate aEPSS 1.5%CVE-2020-15230HIGHArbitrary file read un VaporEPSS 1.5%CVE-2019-15596—A path traversal in statics-server exists in all version that allows an attacker to perform a path traversal when a symlink is used within tEPSS 1.5%CVE-2026-27825CRITICALMCP Atlassian has an arbitrary file write leading to arbitrary code execution via unconstrained download_path in confluence_download_attachmentEPSS 1.5%CVE-2022-31159HIGHPartial Path Traversal in com.amazonaws:aws-java-sdk-s3 EPSS 1.5%CVE-2020-13377HIGHThe web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attackerEPSS 1.5%CVE-2026-5489MEDIUMDriveLock Directory Traversal Information Disclosure VulnerabilityEPSS 1.5%CVE-2026-23482HIGHBlinko: Unauthorized Arbitrary File Read - /api/file/tempEPSS 1.5%CVE-2024-4346CRITICALStartklar Elementor Addons <= 1.7.13 - Unauthenticated Arbitrary File DeletionEPSS 1.5%CVE-2020-12147MEDIUMUnauthorized queries against the Silver Peak Unity OrchestratorTM MySQL database.EPSS 1.5%CVE-2026-45454MEDIUMMicrosoft SharePoint Remote Code Execution VulnerabilityEPSS 1.5%CVE-2026-7411CRITICALIn Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauEPSS 1.5%