Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2019-5444—Path traversal vulnerability in version up to v1.1.3 in serve-here.js npm module allows attackers to list any file in arbitrary folder.EPSS 1.5%CVE-2022-34822CRITICALPath traversal vulnerability in CLUSTERPRO X 5.0 for Windows and earlier, EXPRESSCLUSTER X 5.0 for Windows and earlier, CLUSTERPRO X 5.0 SinEPSS 1.5%CVE-2022-45867HIGHMyBB before 1.8.33 allows Directory Traversal. The Admin CP Languages module allows remote authenticated users, with high privileges, to achEPSS 1.5%CVE-2024-34313CRITICALAn issue in VPL Jail System up to v4.0.2 allows attackers to execute a directory traversal via a crafted request to a public endpoint.EPSS 1.5%CVE-2016-10561—Bitty is a development web server tool that functions similar to `python -m SimpleHTTPServer`. Version 0.2.10 has a directory traversal vulnEPSS 1.5%CVE-2020-7535—A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal' Vulnerability Type) vulnerability exists in the Web EPSS 1.5%CVE-2024-28698CRITICALDirectory Traversal vulnerability in Marimer LLC CSLA .Net before 8.0 allows a remote attacker to execute arbitrary code via a crafted scripEPSS 1.5%CVE-2022-27620MEDIUMImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology SSO Server befoEPSS 1.5%CVE-2023-36827HIGHFides vulnerable to Path Traversal in Webserver APIEPSS 1.5%CVE-2024-9415HIGHPath Traversal in transformeroptimus/superagiEPSS 1.5%CVE-2019-5438—Path traversal using symlink in npm harp module versions <= 0.29.0.EPSS 1.5%CVE-2021-42542HIGHEmerson WirelessHART GatewayEPSS 1.5%CVE-2025-6794CRITICALMarvell QConvergeConsole saveAsText Directory Traversal Remote Code Execution VulnerabilityEPSS 1.5%CVE-2022-33164HIGHIBM Security Directory Server path traversalEPSS 1.5%CVE-2023-27066MEDIUMDirectory Traversal vulnerability in Site Core Experience Platform 10.2 and earlier allows authenticated remote attackers to download arbitrEPSS 1.5%CVE-2018-3713—angular-http-server node module suffers from a Path Traversal vulnerability due to lack of validation of possibleFilename, which allows a maEPSS 1.5%CVE-2022-47027CRITICALTimmystudios Fast Typing Keyboard v1.275.1.162 allows unauthorized apps to overwrite arbitrary files in its internal storage via a dictionarEPSS 1.5%CVE-2023-42000CRITICALArcserve UDP Agent Unauthenticated Path Traversal File Upload EPSS 1.5%CVE-2022-36327MEDIUMPath traversal vulnerability leading to an arbitrary file write in Western Digital devicesEPSS 1.5%CVE-2023-26578HIGHArbitrary File Upload to Web Root In IDAttend’s IDWeb ApplicationEPSS 1.5%