Fallos del tipo CWE-285

1587 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2019-13416—Search Guard versions before 24.3 had an issue when Cross Cluster Search (CCS) was enabled, authenticated users are always authorized on theEPSS 1.0%CVE-2021-21432HIGHReject unauthorized access with GitHub PATsEPSS 1.0%CVE-2017-0892—Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to EPSS 1.0%CVE-2025-23042HIGHGradio Blocked Path ACL Bypass VulnerabilityEPSS 1.0%CVE-2021-42330HIGHShinHer Information Co., LTD. ShinHer StudyOnline System - Improper Authorization-1EPSS 1.0%CVE-2020-5240HIGH2FA bypass through deleting devices in wagtail-2faEPSS 1.0%CVE-2022-31025LOWInvite bypasses user approval in DiscourseEPSS 1.0%CVE-2025-48063MEDIUMXWiki Platform Security Authorization Bridge allows users with just edit right can enforce required rights with programming rightEPSS 1.0%CVE-2019-13554—GE Mark VIe Controller has an unsecured Telnet protocol that may allow a user to create an authenticated session using generic default credeEPSS 1.0%CVE-2025-24418HIGHAdobe Commerce | Improper Authorization (CWE-285)EPSS 1.0%CVE-2022-31247CRITICALRancher: Downstream cluster privilege escalation through cluster and project role template binding (CRTB/PRTB)EPSS 1.0%CVE-2021-22861—Improper access control in GitHub Enterprise Server leading to unauthorized write access to forkable repositoriesEPSS 1.0%CVE-2022-26857CRITICALDell OpenManage Enterprise Versions 3.8.3 and prior contain an improper authorization vulnerability. A remote authenticated malicious user wEPSS 0.9%CVE-2023-3805HIGHXiamen Four Letter Video Surveillance Management System Login UserInfoAction.class improper authorizationEPSS 0.9%CVE-2026-58277HIGHMicrosoft SharePoint Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-39341MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2022-39342MEDIUMOpenFGA Authorization BypassEPSS 0.9%CVE-2017-2589HIGHIt was discovered that the hawtio servlet 1.4 uses a single HttpClient instance to proxy requests with a persistent cookie store (cookies arEPSS 0.9%CVE-2018-0393—A Read-Only User Effect Change vulnerability in the Policy Builder interface of Cisco Policy Suite could allow an authenticated, remote attaEPSS 0.9%CVE-2021-3616CRITICALA vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow an unauthorized user to view device information, alter EPSS 0.9%