Fallos del tipo CWE-276

952 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2025-48950MEDIUMMaxKB Python Sandbox Bypass in Function LibraryEPSS 0.4%CVE-2025-49006HIGHWasp has case insensitive OAuth ID vulnerabilityEPSS 0.4%CVE-2018-11454A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA EPSS 0.4%CVE-2024-48572MEDIUMA User enumeration vulnerability in AquilaCMS 1.409.20 and prior allows unauthenticated attackers to obtain email addresses via the "Add a uEPSS 0.4%CVE-2026-49157HIGHApache ActiveMQ: Authenticated low-privilege Web users retain Jolokia broker-management capability by defaultEPSS 0.4%CVE-2020-5342HIGHDell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileEPSS 0.4%CVE-2019-20458HIGHAn issue was discovered on Epson Expression Home XP255 20.08.FM10I8 devices. By default, the device comes (and functions) without a passwordEPSS 0.4%CVE-2024-46624HIGHAn issue in InfoDom Performa 365 v4.0.1 allows authenticated attackers to elevate their privileges to Administrator via a crafted payload seEPSS 0.4%CVE-2017-7968An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. EPSS 0.4%CVE-2024-22301MEDIUMWordPress Albo Pretorio Online Plugin <= 4.6.6 is vulnerable to Sensitive Data ExposureEPSS 0.4%CVE-2022-44557HIGHThe SmartTrimProcessEvent module has a vulnerability of obtaining the read and write permissions on arbitrary system files. Successful exploEPSS 0.4%CVE-2023-32996MEDIUMA missing permission check in Jenkins SAML Single Sign On(SSO) Plugin 2.0.0 and earlier allows attackers with Overall/Read permission to senEPSS 0.4%CVE-2023-29131HIGHA vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5). Affected device consists of an incorrect default value in the EPSS 0.4%CVE-2026-32983MEDIUMSSL/TLS Renegotiation DoS in Wazuh Manager authd serviceEPSS 0.4%CVE-2024-54751CRITICALCOMFAST CF-WR630AX v2.7.0.2 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in asEPSS 0.4%CVE-2025-43596HIGHMSP360 Backup (for Windows) insecure filesystem permissionsEPSS 0.4%CVE-2024-44228HIGHThis issue was addressed with improved permissions checking. This issue is fixed in Xcode 16. An app may be able to inherit Xcode permissionEPSS 0.4%CVE-2020-13533CRITICALA privilege escalation vulnerability exists in Dream Report 5 R20-2. IIn the default configuration, the following registry keys, which referEPSS 0.4%CVE-2023-6273MEDIUMPermission management vulnerability in the module for disabling Sound Booster. Successful exploitation of this vulnerability may cause featuEPSS 0.4%CVE-2021-20037SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalatiEPSS 0.4%