Fallos del tipo CWE-281

225 resultados

Preservação inadequada de permissões

É quando um sistema copia, move ou cria arquivos, diretórios ou outros recursos sem manter ou validar corretamente as permissões originais, resultando em acesso indevido. Um atacante pode ganhar acesso a dados sensíveis ou executar operações que não deveria poder fazer porque as permissões foram perdidas, relaxadas ou não propagadas corretamente.

Ejemplo

Um backup automático copia arquivos de um diretório protegido (modo 600) para uma pasta temporária, mas o processo não preserva as permissões originais. Os arquivos acabam com permissões padrão (644), permitindo que qualquer usuário do sistema leia dados sensíveis que deveriam ser privados.

Cómo mitigar

Ao copiar, mover ou criar recursos, sempre preserve explicitamente as permissões originais usando APIs que suportam isso (como `cp -p`, `shutil.copystat()` em Python, ou equivalentes). Valide permissões antes e depois da operação e teste cenários onde dados sensíveis são envolvidos.

CVE-2025-7346HIGHAny unauthenticated attacker can bypass the localhost restrictions posed by the application and utilize this to create arbitrary packagesEPSS 0.3%CVE-2026-44832HIGHSnipe-IT: Privilege Escalation via API Permissions AssignmentEPSS 0.3%CVE-2024-39902MEDIUMTuleap's recursive permissions to document manager folder are not properly appliedEPSS 0.3%CVE-2024-50930HIGHAn issue in Silicon Labs Z-Wave Series 500 v6.84.0 allows attackers to execute arbitrary code.EPSS 0.3%CVE-2025-27703HIGHPrivilege escalation in the management console of Absolute Secure Access prior to version 13.54EPSS 0.3%CVE-2021-41089LOW`docker cp` allows unexpected chmod of host filesEPSS 0.3%CVE-2023-2993MEDIUMA valid, authenticated user with limited privileges may be able to use specifically crafted web management server API calls to execute a limEPSS 0.3%CVE-2023-32355—A logic issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.7.7, macOS Monterey 12.6.6, macOS VenturEPSS 0.3%CVE-2026-40767HIGHWordPress wpForo Forum plugin < 3.0.2 - Broken Access Control vulnerabilityEPSS 0.3%CVE-2024-53994MEDIUMPotential bypass of chat permissions in DiscourseEPSS 0.3%CVE-2022-48296MEDIUMThe SystemUI has a vulnerability in permission management. Successful exploitation of this vulnerability may cause users to receive broadcasEPSS 0.3%CVE-2024-44223MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.1. An attacker with physical access to aEPSS 0.3%CVE-2024-3545MEDIUMImproper permission handling in the vault offline cache feature in Devolutions Remote Desktop Manager 2024.1.20 and earlier on windows and DEPSS 0.3%CVE-2024-40824HIGHThis issue was addressed through improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, wEPSS 0.3%CVE-2022-31608HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in an optional D-Bus configuration file, where a local user with basic capabiliEPSS 0.3%CVE-2023-28647MEDIUMApp pin of the iOS app can be bypassed in Nextcloud iOSEPSS 0.3%CVE-2026-4360LOWTarfile.extract() doesn't fully respect filter parameterEPSS 0.3%CVE-2025-21541MEDIUMVulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Admin Screens and Grants UI). Supported versions that aEPSS 0.3%CVE-2024-37649MEDIUMInsecure Permissions vulnerability in SecureSTATION v.2.5.5.3116-S50-SMA-B20160811A and before allows a physically proximate attacker to obtEPSS 0.3%CVE-2026-34600MEDIUMJoplin Server delta API returns note content after share access is revokedEPSS 0.3%