Fallos del tipo CWE-284

7073 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2019-10200—A flaw was discovered in OpenShift Container Platform 4 where, by default, users with access to create pods also have the ability to schedulEPSS 1.3%CVE-2023-1834CRITICALRockwell Automation Kinetix 5500 Vulnerable to Open Port ExploitationEPSS 1.3%CVE-2025-2553MEDIUMD-Link DIR-618/DIR-605L formVirtualServ access controlEPSS 1.3%CVE-2025-30433CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15EPSS 1.2%CVE-2024-45489CRITICALArc before 2024-08-26 allows remote code execution in JavaScript boosts. Boosts that run JavaScript cannot be shared by default; however (beEPSS 1.2%CVE-2023-36722MEDIUMActive Directory Domain Services Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-24197—wpDataTables < 3.4.2 - Improper Access Control leading to Table Permission TakeoverEPSS 1.2%CVE-2020-13675—Drupal's JSON:API and REST/File modules allow file uploads through their HTTP APIs. The modules do not correctly run all file validation, whEPSS 1.2%CVE-2024-43600HIGHMicrosoft Office Elevation of Privilege VulnerabilityEPSS 1.2%CVE-2019-10964HIGHMedtronic MiniMed 508 and Paradigm Series Insulin Pumps Improper Access ControlEPSS 1.2%CVE-2020-14312—A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat EnterpriseEPSS 1.2%CVE-2021-40404MEDIUMAn authentication bypass vulnerability exists in the cgiserver.cgi Login functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-EPSS 1.2%CVE-2022-1553HIGHLeaking password protected articles content due to improper access control in publify/publifyEPSS 1.2%CVE-2021-1389MEDIUMCisco IOS XR and Cisco NX-OS Software IPv6 Access Control List Bypass VulnerabilityEPSS 1.2%CVE-2025-58751LOWVite middleware may serve files starting with the same name with the public directoryEPSS 1.2%CVE-2022-0133MEDIUMImproper Access Control in chocobozzz/peertubeEPSS 1.2%CVE-2022-0203HIGHImproper Access Control in crater-invoice/craterEPSS 1.2%CVE-2023-32632HIGHA command execution vulnerability exists in the validate.so diag_ping_start functionality of Yifan YF325 v1.0_20221108. A specially crafted EPSS 1.2%CVE-2026-5786HIGHAn Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacEPSS 1.2%CVE-2026-9614HIGHAn Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain aEPSS 1.2%