Fallos del tipo CWE-284

7074 resultados

Controle de acesso insuficiente ou ausente

A aplicação não valida corretamente quem pode acessar determinado recurso (arquivo, API, função, dados), permitindo que usuários não autorizados façam operações que deveriam estar bloqueadas. É um dos problemas mais comuns em segurança: sem autenticação e autorização robustas, qualquer um consegue fazer o que não deveria.

Ejemplo

Um admin panel acessível via /admin sem login real, ou uma API que retorna dados de qualquer usuário basta mudar um ID na URL sem verificar se você tem permissão. Outro caso: arquivo de configuração com credenciais exposto publicamente porque a aplicação não define permissões de leitura no servidor.

Cómo mitigar

Implemente autenticação forte (sessões, tokens JWT) e autorização em toda operação sensível — verifique explicitamente se o usuário logado tem permissão antes de retornar dados ou executar ações. Use listas de controle de acesso (ACL) ou Role-Based Access Control (RBAC), e nunca confie em IDs de usuário vindos do cliente sem validação server-side.

CVE-2024-43456MEDIUMWindows Remote Desktop Services Tampering VulnerabilityEPSS 0.7%CVE-2016-4427—In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.EPSS 0.7%CVE-2020-2500CRITICALThis improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensEPSS 0.7%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2022-4331MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15EPSS 0.7%CVE-2023-46712MEDIUMA improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacEPSS 0.7%CVE-2023-0319MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.EPSS 0.7%CVE-2017-16766—An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 aEPSS 0.7%CVE-2025-30460HIGHA permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOSEPSS 0.7%CVE-2025-2218MEDIUMLoveCards LoveCardsV2 Setting other access controlEPSS 0.7%CVE-2025-43233CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13EPSS 0.7%CVE-2024-1308HIGHWooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink ModificationEPSS 0.7%CVE-2023-22335—Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attEPSS 0.7%CVE-2024-45432HIGHOpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The EPSS 0.7%CVE-2024-10993MEDIUMCodezips Online Institute Management System manage_website.php unrestricted uploadEPSS 0.7%CVE-2022-4689HIGHImproper Access Control in usememos/memosEPSS 0.7%CVE-2023-6773MEDIUMCodeAstro POS and Inventory Management System User Creation register_account access controlEPSS 0.7%CVE-2024-13104MEDIUMD-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access controlEPSS 0.7%CVE-2023-0661MEDIUMImproper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. EPSS 0.7%