Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-33897MEDIUMA directory traversal vulnerability exists in the web_server /ajax/remove/ functionality of Robustel R1510 3.1.16. A specially-crafted netwoEPSS 1.5%CVE-2024-9224MEDIUMHello World <= 2.1.1 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 1.5%CVE-2020-4053LOWPath Traversal in Helm Plugin ArchiveEPSS 1.5%CVE-2020-29026CRITICALA directory traversal vulnerability exists in the file upload function of the GateManager that allows an authenticated attacker with adminisEPSS 1.5%CVE-2024-36116HIGHPath traversal in Reposilite javadoc file expansionEPSS 1.5%CVE-2021-34860MEDIUMThis vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of D-Link DAP-2020 1.01rc00EPSS 1.5%CVE-2021-4463HIGHLongjing Technology BEMS API <= 1.21 Remote Arbitrary File DownloadEPSS 1.5%CVE-2025-66480CRITICALWildfire has Arbitrary File Upload via Directory Traversal in UploadFileActionEPSS 1.5%CVE-2025-49656HIGHApache Jena: Administrative users can create files outside the server directory space via the admin UIEPSS 1.5%CVE-2020-5370HIGHDell EMC OpenManage Enterprise (OME) versions prior to 3.4 contain an arbitrary file overwrite vulnerability. A remote authenticated malicioEPSS 1.5%CVE-2026-57872HIGHGV-LPC2011/LPC2211 - unauthorized directory traversal vulnerability (get_fcont.cgi)EPSS 1.5%CVE-2025-6798HIGHMarvell QConvergeConsole deleteAppFile Directory Traversal Arbitrary File Deletion VulnerabilityEPSS 1.5%CVE-2021-41131HIGHClient metadata path-traversal in python-tufEPSS 1.5%CVE-2021-21272HIGHzip slip in ORASEPSS 1.4%CVE-2023-26111HIGHAll versions of the package @nubosoftware/node-static; all versions of the package node-static are vulnerable to Directory Traversal due to EPSS 1.4%CVE-2021-21908MEDIUMSpecially-crafted command line arguments can lead to arbitrary file deletion. The handle_delete function does not attempt to sanitize or othEPSS 1.4%CVE-2022-39034MEDIUMSmart eVision - Path Traversal -2EPSS 1.4%CVE-2022-41231MEDIUMJenkins Build-Publisher Plugin 1.22 and earlier allows attackers with Item/Configure permission to create or replace any config.xml file on EPSS 1.4%CVE-2024-23822MEDIUMThruk Incorrect limitation of a pathname to a restricted directory (Path Traversal) (CWE-22)EPSS 1.4%CVE-2022-36065HIGHGrowthBook account creation and file upload vulnerability in self-hosted configurationsEPSS 1.4%