Fallos del tipo CWE-22

5866 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2022-3060HIGHImproper control of a resource identifier in Error Tracking in GitLab CE/EE affecting all versions from 12.7 allows an authenticated attackeEPSS 1.0%CVE-2021-35968MEDIUMLearningdigital.com, Inc. Orca HCM - Path Traversal-2EPSS 1.0%CVE-2026-7311HIGHTinyPNG <= 3.6.13 - Authenticated (Author+) Arbitrary File Deletion via 'convert.path' in 'tiny_compress_images' Post MetaEPSS 1.0%CVE-2020-24855MEDIUMDirectory Traversal vulnerability in easywebpack-cli before 4.5.2 allows attackers to obtain sensitive information via crafted GET request.EPSS 1.0%CVE-2026-33076HIGHRoxy-WI vulnerable to path traversal and arbitrary file writingEPSS 1.0%CVE-2024-1961HIGHPath Traversal leading to Arbitrary File Write and RCE in vertaai/modeldbEPSS 1.0%CVE-2022-47951MEDIUMAn issue was discovered in OpenStack Cinder before 19.1.2, 20.x before 20.0.2, and 21.0.0; Glance before 23.0.1, 24.x before 24.1.1, and 25.EPSS 1.0%CVE-2026-29522HIGHZwickRoell Test Data Management < 3.0.8 Path Traversal LFIEPSS 1.0%CVE-2021-33724—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system contains an Arbitrary File DeletionEPSS 1.0%CVE-2023-22914HIGHA path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN EPSS 1.0%CVE-2025-1336MEDIUMCmsEasy image_admin.php deleteimg_action path traversalEPSS 1.0%CVE-2026-6227HIGHBackWPup <= 5.6.6 - Authenticated (Administrator+) Local File Inclusion via 'block_name' ParameterEPSS 1.0%CVE-2021-33725—A vulnerability has been identified in SINEC NMS (All versions < V1.0 SP2 Update 1). The affected system allows to delete arbitrary files orEPSS 1.0%CVE-2018-16739HIGHAn issue was discovered on certain ABUS TVIP devices. Due to a path traversal in /opt/cgi/admin/filewrite, an attacker can write to files, aEPSS 1.0%CVE-2017-20105MEDIUMSimplessus path traversalEPSS 1.0%CVE-2021-36288HIGHDell VNX2 for File version 8.1.21.266 and earlier, contain a path traversal vulnerability which may lead unauthenticated users to read/writeEPSS 1.0%CVE-2025-13645HIGHModula 2.13.1 - 2.13.2 - Authenticated (Author+) Arbitrary File DeletionEPSS 1.0%CVE-2024-46898HIGHSHIRASAGI prior to v1.19.1 processes URLs in HTTP requests improperly, resulting in a path traversal vulnerability. If this vulnerability isEPSS 1.0%CVE-2023-23760MEDIUMPath traversal in GitHub Enterprise Server leading to remote code executionEPSS 1.0%CVE-2023-26045CRITICALNodeBB vulnerable to path traversal and code execution via prototype vulnerabilityEPSS 1.0%