Fallos del tipo CWE-281

225 resultados

Preservação inadequada de permissões

É quando um sistema copia, move ou cria arquivos, diretórios ou outros recursos sem manter ou validar corretamente as permissões originais, resultando em acesso indevido. Um atacante pode ganhar acesso a dados sensíveis ou executar operações que não deveria poder fazer porque as permissões foram perdidas, relaxadas ou não propagadas corretamente.

Ejemplo

Um backup automático copia arquivos de um diretório protegido (modo 600) para uma pasta temporária, mas o processo não preserva as permissões originais. Os arquivos acabam com permissões padrão (644), permitindo que qualquer usuário do sistema leia dados sensíveis que deveriam ser privados.

Cómo mitigar

Ao copiar, mover ou criar recursos, sempre preserve explicitamente as permissões originais usando APIs que suportam isso (como `cp -p`, `shutil.copystat()` em Python, ou equivalentes). Valide permissões antes e depois da operação e teste cenários onde dados sensíveis são envolvidos.

CVE-2024-54557HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2EPSS 0.5%CVE-2022-31096MEDIUMInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in DiscourseEPSS 0.5%CVE-2024-22404MEDIUMPermissions bypass in Nextcloud with the files zip appEPSS 0.5%CVE-2024-54818HIGHSourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.EPSS 0.5%CVE-2024-22402MEDIUMImproper handling of request URLs in Nextcloud Guests app allows guest users to bypass app allowlistEPSS 0.5%CVE-2024-27795HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to aEPSS 0.5%CVE-2024-30187MEDIUMAnope before 2.0.15 does not prevent resetting the password of a suspended account.EPSS 0.5%CVE-2025-43698CRITICALImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for SEPSS 0.5%CVE-2024-41648HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2024-32882LOWPermission check bypass when editing a model with per-field restrictions in wagtailEPSS 0.5%CVE-2024-41650HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2021-3418—If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validatiEPSS 0.5%CVE-2021-3847—An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the wEPSS 0.5%CVE-2024-50920HIGHInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted EPSS 0.5%CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2021-21379HIGHIt's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macroEPSS 0.5%CVE-2024-36532CRITICALInsecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tEPSS 0.5%CVE-2024-33892MEDIUMInsecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible toEPSS 0.4%CVE-2025-25871HIGHAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.4%CVE-2023-42228HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL ruEPSS 0.4%