Fallos del tipo CWE-285

1587 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2019-7479—A vulnerability in SonicOS allow authenticated read-only admin can elevate permissions to configuration mode. This vulnerability affected SoEPSS 0.9%CVE-2025-30390CRITICALAzure ML Compute Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2023-33189CRITICALIncorrect Authorization with specially crafted requestsEPSS 0.9%CVE-2022-22288HIGHImproper authorization vulnerability in Galaxy Store prior to 4.5.36.5 allows remote app installation of the allowlist.EPSS 0.9%CVE-2020-8119—Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the galleryEPSS 0.9%CVE-2026-32213CRITICALAzure AI Foundry Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2022-23542HIGHOpenFGA Authorization BypassEPSS 0.9%CVE-2022-24083CRITICALPassword authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.EPSS 0.9%CVE-2022-3748CRITICALImproper authorization that can lead to account impersonationEPSS 0.9%CVE-2023-4243HIGHFULL - Customer <= 2.2.3 - Authenticated(Subscriber+) Improper Authorization to Arbitrary Plugin InstallationEPSS 0.9%CVE-2022-3740MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.9 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 priorEPSS 0.9%CVE-2021-41100HIGHAccount takeover when having only access to a user's short lived token in wire-serverEPSS 0.9%CVE-2021-42337MEDIUMTVN-202110009EPSS 0.9%CVE-2018-3829—In Elastic Cloud Enterprise (ECE) versions prior to 1.1.4 it was discovered that a user could scale out allocators on new hosts with an invaEPSS 0.9%CVE-2022-33713—Implicit Intent hijacking vulnerability in Samsung Cloud prior to version 5.2.0 allows attacker to get sensitive information.EPSS 0.9%CVE-2021-0260HIGHJunos OS: SNMP fails to properly perform authorization checks on incoming received SNMP requests.EPSS 0.9%CVE-2020-1998MEDIUMPAN-OS: Improper SAML SSO authorization of shared local usersEPSS 0.9%CVE-2019-3764MEDIUMDell EMC iDRAC7 versions prior to 2.65.65.65, iDRAC8 versions prior to 2.70.70.70 and iDRAC9 versions prior to 3.36.36.36 contain an impropeEPSS 0.9%CVE-2023-29338MEDIUMVisual Studio Code Spoofing VulnerabilityEPSS 0.9%CVE-2024-43731MEDIUMAdobe Experience Manager | Improper Authorization (CWE-285)EPSS 0.9%