Fallos del tipo CWE-22

5867 resultados

Travessia de diretório (path traversal)

A aplicação constrói caminhos de arquivo a partir de entrada do usuário sem validar adequadamente sequências como '../' ou símbolos absolutos, permitindo que um atacante acesse arquivos fora do diretório permitido. Isso expõe dados sensíveis ou permite execução não autorizada de operações no sistema de arquivos.

Ejemplo

Um sistema web que serve documentos de um diretório específico recebe a requisição 'GET /doc?file=../../etc/passwd'. Se não validar a entrada, o código resolve o caminho para fora do diretório restrito e vaza o arquivo de senhas do sistema.

Cómo mitigar

Valide caminhos usando listas brancas de nomes de arquivo permitidos, normalize caminhos (remover '../' e símbolos), use APIs que isolem automaticamente operações em diretório base (ex: chroot, sandbox), e evite concatenar entrada direta em construtores de caminhos. Teste com payloads comuns de path traversal em testes de segurança.

CVE-2024-5153CRITICALStartklar Elementor Addons <= 1.7.15 - Unauthenticated Path Traversal to Arbitrary Directory DeletionEPSS 1.0%CVE-2026-43975MEDIUMApache Wicket: Possible malicious path traversal in FolderUploadsFileManagerEPSS 1.0%CVE-2023-30852MEDIUMPimcore Arbitrary File Read in Admin JS CSS filesEPSS 1.0%CVE-2024-34033HIGHPath Traversal vulnerability in Delta Electronics DIAEnergie EPSS 1.0%CVE-2022-39059HIGHChangingTec MegaServiSignAdapter - Path TraversalEPSS 1.0%CVE-2025-69612MEDIUMA path traversal vulnerability exists in TMS Management Console (version 6.3.7.27386.20250818) from TMS Global Software. The "Download TemplEPSS 1.0%CVE-2023-23169MEDIUMSynapsoft pdfocus 1.17 is vulnerable to local file inclusion and server-side request forgery Directory Traversal.EPSS 1.0%CVE-2024-23833HIGHOpenRefine JDBC Attack VulnerabilityEPSS 1.0%CVE-2025-46120CRITICALAn issue was discovered in CommScope Ruckus Unleashed prior to 200.15.6.212.27 and 200.18.7.1.323, and in Ruckus ZoneDirector prior to 10.5.EPSS 1.0%CVE-2022-39215HIGHThe readDir Endpoint Scope can be Bypassed With Symbolic Links in TauriEPSS 1.0%CVE-2023-36667HIGHCouchbase Server 7.1.4 before 7.1.5 and 7.2.0 before 7.2.1 allows Directory Traversal.EPSS 1.0%CVE-2023-45723HIGHPath Traversal which allows file upload capability affects DRYiCE MyXalyticsEPSS 1.0%CVE-2024-52055HIGHApplication Copy Path Traversal in Wowza Streaming EngineEPSS 1.0%CVE-2026-4944HIGHHardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security ControlEPSS 1.0%CVE-2025-13810MEDIUMjsnjfz WebStack-Guns KaptchaController.java renderPicture path traversalEPSS 1.0%CVE-2021-32008CRITICALLogged-in Administrator may get unrestricted file system accessEPSS 1.0%CVE-2023-26126HIGHAll versions of the package m.static are vulnerable to Directory Traversal due to improper input sanitization of the path being requested viEPSS 1.0%CVE-2026-49297HIGHApache Airflow Google provider: Path traversal via GCS object names → local/SFTP filesystem (GCSToSFTPOperator + GCSTimeSpanFileTransformOperator)EPSS 1.0%CVE-2012-5380MEDIUMUntrusted search path vulnerability in the installation functionality in Ruby 1.9.3-p194, when installed in the top-level C:\ directory, migEPSS 1.0%CVE-2024-10361HIGHArbitrary File Deletion via Path Traversal in danny-avila/librechatEPSS 1.0%