Fallos del tipo CWE-276

952 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2021-20037SonicWall Global VPN Client 4.10.5 installer (32-bit and 64-bit) incorrect default file permission vulnerability leads to privilege escalatiEPSS 0.4%CVE-2025-43595HIGHMSP360 Backup (for Linux) insecure filesystem permissionsEPSS 0.4%CVE-2024-27155HIGHLocal Privilege Escalation and Remote Code Execution using insecure permissionsEPSS 0.4%CVE-2024-36541HIGHInsecure permissions in logging-operator v4.6.0 allows attackers to access sensitive data and escalate privileges by obtaining the service aEPSS 0.4%CVE-2024-48533MEDIUMA discrepancy between responses for valid and invalid e-mail accounts in the Forgot your Login? module of eSoft Planner 3.24.08271-USA allowEPSS 0.4%CVE-2024-56525CRITICALIn Public Knowledge Project (PKP) OJS, OMP, and OPS before 3.3.0.21 and 3.4.x before 3.4.0.8, an XXE attack by the Journal Editor Role can cEPSS 0.4%CVE-2020-15145MEDIUMLocal privilege elevation in Composer-Setup for WindowsEPSS 0.4%CVE-2020-5355MEDIUMThe Dell Isilon OneFS versions 8.2.2 and earlier SSHD process improperly allows Transmission Control Protocol (TCP) and stream forwarding. TEPSS 0.4%CVE-2020-13532CRITICALA privilege escalation vulnerability exists in Dream Report 5 R20-2. In the default configuration, the Syncfusion Dashboard Service service EPSS 0.4%CVE-2025-8432HIGHCentreonBI user account on the MBI server can execute commands as root by modifying script runned by the CRONEPSS 0.4%CVE-2024-6148MEDIUMBypass of GACS Policy Configuration settings in Citrix Workspace app for HTML5EPSS 0.4%CVE-2024-27151HIGHLocal Privilege Escalation and Remote Code Execution using insecure permissionsEPSS 0.4%CVE-2024-21116HIGHVulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are PrioEPSS 0.4%CVE-2023-21216CRITICALIn PMRChangeSparseMemOSMem of physmem_osmem_linux.c, there is a possible arbitrary code execution due to a use after free. This could lead tEPSS 0.4%CVE-2024-47825MEDIUMCIDR deny policies may not take effect when a more narrow CIDR allow is presentEPSS 0.4%CVE-2022-25776HIGHSensitive Data Exposure due to inadequate user permission settingsEPSS 0.4%CVE-2025-40585CRITICALA vulnerability has been identified in Energy Services (All versions with G5DFR). Affected solutions using G5DFR contain default credentialsEPSS 0.4%CVE-2025-24140MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.3. Files downloaded from the internet maEPSS 0.4%CVE-2025-46014HIGHSeveral services in Honor Device Co., Ltd Honor PC Manager v16.0.0.118 was discovered to connect services to the named pipe iMateBookAssistaEPSS 0.4%CVE-2022-29162MEDIUMIncorrect Default Permissions in runcEPSS 0.4%