Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-48285HIGHloadAsync in JSZip before 3.8.0 allows Directory Traversal via a crafted ZIP archive.EPSS 1.4%CVE-2022-31195HIGHPath traversal vulnerability in Simple Archive Format package import in DSpaceEPSS 1.4%CVE-2020-10634—SAE IT-systems FW-50 Remote Telemetry Unit (RTU). A specially crafted request could allow an attacker to view the file structure of the affeEPSS 1.4%CVE-2023-45685CRITICALArbitrary file write via "zip slip" in Titan MFT and Titan SFTP serversEPSS 1.4%CVE-2023-24960HIGHIBM InfoSphere Information Server information disclosureEPSS 1.4%CVE-2024-36512HIGHAn improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.EPSS 1.4%CVE-2026-44225CRITICALPulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read arbitrary user filesEPSS 1.4%CVE-2021-27461—A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow aEPSS 1.4%CVE-2021-29087HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in webapi component in Synology DiskStation ManEPSS 1.4%CVE-2025-24406HIGHAdobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)EPSS 1.4%CVE-2021-32643MEDIUMStaticFile.fromUrl can leak presence of a directoryEPSS 1.4%CVE-2021-21269HIGHPath Traversal in KeymakerEPSS 1.4%CVE-2024-11150CRITICALWordPress User Extra Fields <= 16.6 - Unauthenticated Arbitrary File DeletionEPSS 1.4%CVE-2026-24770CRITICALRAGFlow Affected by Zip Slip Remote Code Execution (RCE) in MinerUParserEPSS 1.4%CVE-2025-27519CRITICALCognita Arbitrary File WriteEPSS 1.4%CVE-2024-31860MEDIUMApache Zeppelin: Path traversal vulnerabilityEPSS 1.4%CVE-2022-45866MEDIUMqpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversaEPSS 1.4%CVE-2025-4138HIGHBypassing extraction filter to create symlinks to arbitrary targets outside extraction directoryEPSS 1.4%CVE-2022-0493—String Locator < 2.5.0 - Admin+ Arbitrary File ReadEPSS 1.4%CVE-2023-6972CRITICALBackup Migration <= 1.3.9 - Unauthenticated Path Traversal to Arbitrary File DeletionEPSS 1.4%