Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2021-1532MEDIUMCisco TelePresence Collaboration Endpoint and RoomOS Software Arbitrary File Read VulnerabilityEPSS 1.4%CVE-2022-46137HIGHAeroCMS v0.0.1 is vulnerable to Directory Traversal. The impact is: obtain sensitive information (remote). The component is: AeroCMS v0.0.1.EPSS 1.4%CVE-2022-2261—WPide < 3.0 - Admin+ Local File InclusionEPSS 1.4%CVE-2025-4517CRITICALArbitrary writes via tarfile realpath overflowEPSS 1.4%CVE-2022-44748HIGHUploading workflows to KNIME Server may override arbitrary file system contentsEPSS 1.4%CVE-2026-36723HIGHAn unrestricted file rename vulnerability in the /api/create-user component of bookcars v8.3 allows authenticated attackers to leverage direEPSS 1.4%CVE-2019-3902MEDIUMA flaw was found in Mercurial before 4.9. It was possible to use symlinks and subrepositories to defeat Mercurial's path-checking logic and EPSS 1.4%CVE-2025-66262CRITICALArbitrary File Overwrite via Tar Extraction Path TraversalEPSS 1.4%CVE-2022-34271HIGHApache Atlas: zip path traversal in import functionalityEPSS 1.4%CVE-2021-21907MEDIUMA directory traversal vulnerability exists in the CMA CLI getenv command functionality of Garrett Metal Detectors’ iC Module CMA Version 5.0EPSS 1.4%CVE-2024-40617MEDIUMPath traversal vulnerability exists in FUJITSU Network Edgiot GW1500 (M2M-GW for FENICS). If a remote authenticated attacker with User ClassEPSS 1.4%CVE-2021-41185HIGHDownload file outside intended directoryEPSS 1.4%CVE-2025-47492HIGHWordPress Drag and Drop File Upload for Elementor Forms plugin <= 1.4.3 - Arbitrary File Deletion VulnerabilityEPSS 1.4%CVE-2024-7924MEDIUMZZCMS list.php path traversalEPSS 1.4%CVE-2025-27782HIGHApplio allows arbitrary file write in inference.pyEPSS 1.4%CVE-2018-3715—glance node module before 3.0.4 suffers from a Path Traversal vulnerability due to lack of validation of path passed to it, which allows a mEPSS 1.4%CVE-2022-45381HIGHJenkins Pipeline Utility Steps Plugin 2.13.1 and earlier does not restrict the set of enabled prefix interpolators and bundles versions of AEPSS 1.4%CVE-2019-25687CRITICALPegasus CMS 1.0 Remote Code Execution via extra_fields.phpEPSS 1.4%CVE-2026-59866CRITICALKiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceNameEPSS 1.4%CVE-2022-39345CRITICALGin-vue-admin arbitrary file upload vulnerability caused by path traversalEPSS 1.4%