Fallos del tipo CWE-277

71 resultados

Permissões herdadas inseguras

Fraqueza onde um recurso (arquivo, diretório, processo) herda permissões de um elemento pai de forma insegura, permitindo acesso não autorizado. O desenvolvedor ou administrador não valida ou restringe essas permissões herdadas, deixando o recurso exposto a usuários ou processos que não deveriam ter acesso.

Ejemplo

Um arquivo de configuração com credenciais é criado dentro de um diretório com permissões 777 (leitura/escrita/execução para todos). O arquivo herda essas permissões amplas do diretório pai, permitindo que qualquer usuário do sistema leia as credenciais, mesmo que o arquivo em si fosse destinado apenas ao administrador.

Cómo mitigar

Defina permissões explícitas e restritivas no recurso, independente das permissões do elemento pai (use umask adequado ou ACLs). Valide e audit regularmente as permissões de diretórios e arquivos críticos, especialmente para dados sensíveis ou executáveis, sem confiar na herança padrão do sistema.

CVE-2025-56019MEDIUMAn insecure permission vulnerability exists in the Agasta Easytouch+ version 9.3.97 The device allows unauthorized mobile applications to coEPSS 0.3%CVE-2025-64185MEDIUMOpen OnDemand RPM packages create world writable locationsEPSS 0.3%CVE-2023-29065MEDIUMOverly Permissive Access PolicyEPSS 0.3%CVE-2020-5343HIGHDell Client platforms restored using a Dell OS recovery image downloaded before December 20, 2019, may contain an insecure inherited permissEPSS 0.3%CVE-2025-36104MEDIUMIBM Storage Scale information disclosureEPSS 0.3%CVE-2025-22448MEDIUMInsecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user toEPSS 0.3%CVE-2025-9039MEDIUMInformation Disclosure in Amazon ECS Container AgentEPSS 0.3%CVE-2024-36691MEDIUMInsecure permissions in the AdminController.AjaxSave() method of PPGo_Jobs v2.8.0 allows authenticated attackers to arbitrarily modify usersEPSS 0.3%CVE-2024-27847HIGHThis issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS MontereyEPSS 0.2%CVE-2024-23233HIGHThis issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. Entitlements and privacy permissions granted to thiEPSS 0.2%CVE-2025-65111LOWSpiceDB's LookupResources with Multiple Entrypoints across Different Definitions Can Return Incomplete ResultsEPSS 0.2%CVE-2018-25111MEDIUMdjango-helpdesk before 1.0.0 allows Sensitive Data Exposure because of os.umask(0) in models.py.EPSS 0.2%CVE-2024-27848HIGHThis issue was addressed with improved permissions checking. This issue is fixed in iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5. A maliciousEPSS 0.2%CVE-2024-29417HIGHInsecure Permissions vulnerability in e-trust Horacius 1.0, 1.1, and 1.2 allows a local attacker to escalate privileges via the password resEPSS 0.2%CVE-2025-11395MEDIUMPodman: arbitrary file write when importing oci archiveEPSS 0.2%CVE-2024-27825HIGHA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.2%CVE-2023-34997MEDIUMInsecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authEPSS 0.2%CVE-2023-34314MEDIUMInsecure inherited permissions in some Intel(R) Simics Simulator software before version 1.7.2 may allow an authenticated user to potentiallEPSS 0.2%CVE-2023-39230MEDIUMInsecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user EPSS 0.2%CVE-2024-45599LOWTCC Bypass in Cursor's macOS ApplicationEPSS 0.2%