Fallos del tipo CWE-22

5868 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-25895HIGHDirectory TraversalEPSS 1.3%CVE-2022-23602HIGHNim's rst parser sandboxed mode allows include which can embed any local fileEPSS 1.3%CVE-2022-21192HIGHAll versions of the package serve-lite are vulnerable to Directory Traversal due to missing input sanitization or other checks and protectioEPSS 1.3%CVE-2023-27105CRITICALA vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X PortabEPSS 1.3%CVE-2022-25936HIGHVersions of the package servst before 2.0.3 are vulnerable to Directory Traversal due to improper sanitization of the filePath variable. EPSS 1.3%CVE-2023-46177MEDIUMIBM MQ Appliance information disclosureEPSS 1.3%CVE-2018-1103MEDIUMOpenshift Enterprise source-to-image before version 1.1.10 is vulnerable to an improper validation of user input. An attacker who could tricEPSS 1.3%CVE-2024-9676MEDIUMPodman: buildah: cri-o: symlink traversal vulnerability in the containers/storage library can cause denial of service (dos)EPSS 1.3%CVE-2018-16485—Path Traversal vulnerability in module m-server <1.4.1 allows malicious user to access unauthorized content of any file in the directory treEPSS 1.3%CVE-2026-91989HIGHatomic-agents-stack before 1.1.0 Path Traversal via dashboard serve.pyEPSS 1.3%CVE-2021-34638MEDIUMWordPress Download Manager <= 3.1.24 Authenticated Directory TraversalEPSS 1.3%CVE-2026-59864CRITICALKiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensionsEPSS 1.3%CVE-2024-21633HIGHArbitrary file write on DecodingEPSS 1.3%CVE-2025-32799MEDIUMConda-build Vulnerable to Path Traversal via Malicious Tar FileEPSS 1.3%CVE-2025-6806HIGHMarvell QConvergeConsole decryptFile Directory Traversal Arbitrary File Write VulnerabilityEPSS 1.3%CVE-2025-6801HIGHMarvell QConvergeConsole saveNICParamsToFile Directory Traversal Arbitrary File Write VulnerabilityEPSS 1.3%CVE-2022-34375HIGHDell Container Storage Modules 1.2 contains a path traversal vulnerability in goiscsi and gobrick libraries. A remote authenticated maliciouEPSS 1.3%CVE-2026-45140CRITICALChamilo LMS CStudio upload flow allows unauthenticated remote code executionEPSS 1.3%CVE-2022-25931HIGHDirectory TraversalEPSS 1.3%CVE-2022-20724MEDIUMCisco IOx Application Hosting Environment VulnerabilitiesEPSS 1.3%