Fallos del tipo CWE-281

225 resultados

Preservação inadequada de permissões

É quando um sistema copia, move ou cria arquivos, diretórios ou outros recursos sem manter ou validar corretamente as permissões originais, resultando em acesso indevido. Um atacante pode ganhar acesso a dados sensíveis ou executar operações que não deveria poder fazer porque as permissões foram perdidas, relaxadas ou não propagadas corretamente.

Ejemplo

Um backup automático copia arquivos de um diretório protegido (modo 600) para uma pasta temporária, mas o processo não preserva as permissões originais. Os arquivos acabam com permissões padrão (644), permitindo que qualquer usuário do sistema leia dados sensíveis que deveriam ser privados.

Cómo mitigar

Ao copiar, mover ou criar recursos, sempre preserve explicitamente as permissões originais usando APIs que suportam isso (como `cp -p`, `shutil.copystat()` em Python, ou equivalentes). Valide permissões antes e depois da operação e teste cenários onde dados sensíveis são envolvidos.

CVE-2025-43701HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data.  This impaEPSS 0.4%CVE-2025-43697HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (DataMapper) allows exposure of encrypted data. This impacts OmnEPSS 0.4%CVE-2024-23464HIGHZscaler bypass with administrative privileges on WindowsEPSS 0.4%CVE-2025-43700HIGHImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of encrypted data.  This impacts OmEPSS 0.4%CVE-2025-25711HIGHAn issue in dtp.ae tNexus Airport View v.2.8 allows a remote attacker to escalate privileges via the ProfileID value to the [/tnexus/rest/adEPSS 0.4%CVE-2022-41963LOWBigBlueButton contains Improper Preservation of Permissions for whiteboardEPSS 0.4%CVE-2024-9333MEDIUMPermission bypass in M-Files Connector for CopilotEPSS 0.4%CVE-2024-44211HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15.1. An app may be able to access user-EPSS 0.4%CVE-2023-45807MEDIUMOpenSearch Issue with tenant read-only permissionsEPSS 0.4%CVE-2024-44193HIGHA logic issue was addressed with improved restrictions. This issue is fixed in iTunes 12.13.3 for Windows. A local attacker may be able to eEPSS 0.4%CVE-2024-33921MEDIUMWordPress ReviewX plugin <= 1.6.21 - Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-50921MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause a Denial of Service (DoS) via repeaEPSS 0.4%CVE-2024-50924MEDIUMInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to cause disrupt communications between the EPSS 0.4%CVE-2024-38361LOWPermissions processing error in spacedbEPSS 0.4%CVE-2024-37575HIGHThe Mister org.mistergroup.shouldianswer application 1.4.264 for Android enables any installed application (with no permissions) to place phEPSS 0.4%CVE-2024-57698HIGHAn issue in modernwms v.1.0 allows an attacker view the MD5 hash of the administrator password and other attributes without authentication, EPSS 0.4%CVE-2026-44947MEDIUMStale PSA ClusterRoleBinding Persists After RoleTemplate Downgrade in RancherEPSS 0.4%CVE-2025-32697NONECascading protection is not preventing file reversionsEPSS 0.4%CVE-2023-4996MEDIUMLocal privilege escalation EPSS 0.4%CVE-2022-0330—A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code onEPSS 0.4%