Fallos del tipo CWE-276

952 resultados

Permissões padrão incorretas

Ocorre quando um software cria arquivos, diretórios ou recursos com permissões padrão muito permissivas, expondo dados sensíveis a usuários não autorizados do sistema. O risco é que qualquer outro processo ou usuário consegue ler, modificar ou deletar informações que deveriam ser privadas.

Ejemplo

Um aplicativo cria um arquivo de configuração com senha de banco de dados com permissões 0644 (legível por qualquer usuário), em vez de 0600 (só o dono). Outro usuário no mesmo servidor consegue ler esse arquivo e obtém as credenciais.

Cómo mitigar

Defina permissões explícitas e restritivas no ato da criação (use umask apropriado, chmod, ou APIs de segurança). Sempre revise e documente quais permissões cada recurso deve ter, testando a realidade no sistema de arquivos ou controle de acesso após o deploy.

CVE-2023-29731HIGHSoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can lEPSS 0.8%CVE-2023-22651CRITICALImproper Privilege Management vulnerability in SUSE Rancher allows Privilege Escalation. A failure in the update logic of Rancher's admissioEPSS 0.8%CVE-2021-34164HIGHPermissions vulnerability in LIZHIFAKA v.2.2.0 allows authenticated attacker to execute arbitrary commands via the set password function in EPSS 0.8%CVE-2020-27228HIGHAn incorrect default permissions vulnerability exists in the installation functionality of OpenClinic GA 5.173.3. Overwriting the binary canEPSS 0.8%CVE-2023-27647HIGHAn issue found in DUALSPACE Lock Master v.2.2.4 allows a local attacker to cause a denial of service or gain sensitive information via the cEPSS 0.7%CVE-2019-20457CRITICALAn issue was discovered on Brother MFC-J491DW C1806180757 devices. The printer's web-interface password hash can be retrieved without authenEPSS 0.7%CVE-2023-1809HIGHDownload Manager Pro < 6.3.0 - Unauthenticated Sensitive Information DisclosureEPSS 0.7%CVE-2024-57604CRITICALAn issue in MaysWind ezBookkeeping 0.7.0 allows a remote attacker to escalate privileges via the token component.EPSS 0.7%CVE-2021-3579HIGHIncorrect Default Permissions vulnerability in bdservicehost.exe and Vulnerability.Scan.exeEPSS 0.7%CVE-2022-25943The installer of WPS Office for Windows versions prior to v11.2.0.10258 fails to configure properly the ACL for the directory where the servEPSS 0.7%CVE-2022-42127MEDIUMThe Friendly Url module in Liferay Portal 7.4.3.5 through 7.4.3.36, and Liferay DXP 7.4 update 1 though 36 does not properly check user permEPSS 0.7%CVE-2023-35080HIGHA vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploiEPSS 0.7%CVE-2022-42128MEDIUMThe Hypermedia REST APIs module in Liferay Portal 7.4.1 through 7.4.3.4, and Liferay DXP 7.4 GA does not properly check permissions, which aEPSS 0.7%CVE-2023-38370HIGHIBM Security Access Manager Docker information disclosureEPSS 0.7%CVE-2024-22889MEDIUMDue to incorrect access control in Plone version v6.0.9, remote attackers can view and list all files hosted on the website via sending a crEPSS 0.7%CVE-2025-27677CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Symbolic Links For Unprivileged FilEPSS 0.7%CVE-2022-48199HIGHSoftPerfect NetWorx 7.1.1 on Windows allows an attacker to execute a malicious binary with potentially higher privileges via a low-privilegeEPSS 0.7%CVE-2020-13535CRITICALA privilege escalation vulnerability exists in Kepware LinkMaster 3.0.94.0. In its default configuration, an attacker can globally overwriteEPSS 0.7%CVE-2025-27682CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005.EPSS 0.7%CVE-2024-12564MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in ODA CDE inWEB SDK before 2025.3EPSS 0.7%