Fallos del tipo CWE-276

953 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2022-23454HIGHPotential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromEPSS 0.2%CVE-2022-44548MEDIUMThere is a vulnerability in permission verification during the Bluetooth pairing process. Successful exploitation of this vulnerability may EPSS 0.2%CVE-2022-23453HIGHPotential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromEPSS 0.2%CVE-2026-48935LOWA flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-reaEPSS 0.2%CVE-2023-4088CRITICALMalicious Code Execution Vulnerability in FA Engineering Software ProductsEPSS 0.2%CVE-2023-3116HIGHLiteos-A has a incorrect default permissions vulnerabilityEPSS 0.2%CVE-2025-54530HIGHIn JetBrains TeamCity before 2025.07 privilege escalation was possible due to incorrect directory permissionsEPSS 0.2%CVE-2022-36367MEDIUMIncorrect default permissions in the Intel(R) Support Android application before version v22.02.28 may allow a privileged user to potentiallEPSS 0.2%CVE-2025-24915HIGHWhen installing Nessus Agent to a non-default location on a Windows host, Nessus Agent versions prior to 10.8.3 did not enforce secure permiEPSS 0.2%CVE-2023-35181HIGHSolarWinds Access Rights Manager Incorrect Default Permissions Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-29962MEDIUMInsecure file permission setting that makes files world-readableEPSS 0.2%CVE-2024-10469MEDIUMCERT/CC VINCE versions before 3.0.9 allows authenticated user to access User Management view.EPSS 0.2%CVE-2023-38295HIGHCertain software builds for the TCL 30Z and TCL 10 Android devices contain a vulnerable, pre-installed app that relies on a missing permissiEPSS 0.2%CVE-2022-43701HIGHInsecure directory permissions on installer filesEPSS 0.2%CVE-2024-46464HIGHIn PRIMX ZED Enterprise up to 2024.3, technical files stored in local folders with common user access can be manipulated to render the host EPSS 0.2%CVE-2022-4575MEDIUM A vulnerability due to improper write protection of UEFI variables was reported in the BIOS of some ThinkPad models could allow an attackerEPSS 0.2%CVE-2025-31261MEDIUMA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOEPSS 0.2%CVE-2023-27392MEDIUMIncorrect default permissions in the Intel(R) Support android application before version v23.02.07 may allow a privileged user to potentiallEPSS 0.2%CVE-2025-49842LOWconda-forge-webservices Privilege Escalation Risk via Default Docker Root UserEPSS 0.2%CVE-2025-29504HIGHInsecure Permission vulnerability in student-manage 1 allows a local attacker to escalate privileges via the Unsafe permission verification.EPSS 0.2%