Fallos del tipo CWE-281

225 resultados

Preservação inadequada de permissões

É quando um sistema copia, move ou cria arquivos, diretórios ou outros recursos sem manter ou validar corretamente as permissões originais, resultando em acesso indevido. Um atacante pode ganhar acesso a dados sensíveis ou executar operações que não deveria poder fazer porque as permissões foram perdidas, relaxadas ou não propagadas corretamente.

Ejemplo

Um backup automático copia arquivos de um diretório protegido (modo 600) para uma pasta temporária, mas o processo não preserva as permissões originais. Os arquivos acabam com permissões padrão (644), permitindo que qualquer usuário do sistema leia dados sensíveis que deveriam ser privados.

Cómo mitigar

Ao copiar, mover ou criar recursos, sempre preserve explicitamente as permissões originais usando APIs que suportam isso (como `cp -p`, `shutil.copystat()` em Python, ou equivalentes). Valide permissões antes e depois da operação e teste cenários onde dados sensíveis são envolvidos.

CVE-2024-54880CRITICALSeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts EPSS 0.9%CVE-2024-54465CRITICALA logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileEPSS 0.9%CVE-2024-56973CRITICALInsecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitraryEPSS 0.9%CVE-2021-3523—A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an aEPSS 0.8%CVE-2023-28668CRITICALJenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.EPSS 0.8%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-36062HIGHGrafana folders admin only permission privilege escalationEPSS 0.7%CVE-2023-34672—Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting uEPSS 0.7%CVE-2024-1726MEDIUMQuarkus: security checks for some inherited endpoints performed after serialization in resteasy reactive may trigger a denial of serviceEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2024-41644CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41646CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41645CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41649CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2022-38473HIGHA cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). ThisEPSS 0.7%CVE-2019-14841HIGHA flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attEPSS 0.7%CVE-2023-41939HIGHJenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users fEPSS 0.7%CVE-2021-3414—A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and maEPSS 0.7%CVE-2025-34298HIGHNagios Log Server < 2024R1.3.2 Set Email Privilege EscalationEPSS 0.7%CVE-2023-32552—An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certainEPSS 0.6%