Fallos del tipo CWE-285

1587 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2021-41313—Affected versions of Atlassian Jira Server and Data Center allow authenticated but non-admin remote attackers to edit email batch configuratEPSS 0.9%CVE-2022-30746HIGHMissing caller check in Smart Things prior to version 1.7.85.12 allows attacker to access senstive information remotely using javascript intEPSS 0.9%CVE-2022-36110HIGHNetmaker vulnerable to Insufficient Granularity of Access ControlEPSS 0.9%CVE-2024-11860MEDIUMSourceCodester Best House Rental Management System POST Request ajax.php improper authorizationEPSS 0.9%CVE-2023-0813HIGHNetwork-observability-console-plugin-container: setting loki authtoken configuration to disable or host mode leads to authentication longer being enforcedEPSS 0.9%CVE-2024-26193MEDIUMAzure Migrate Remote Code Execution VulnerabilityEPSS 0.9%CVE-2021-23140CRITICALImproper Authorization vulnerability in Gallagher Command Centre Server allows command line macros to be modified by an unauthorised CommandEPSS 0.9%CVE-2024-3840MEDIUMInsufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation resEPSS 0.9%CVE-2022-29236MEDIUMImproper access control for pencil annotations in BigBlueButtonEPSS 0.9%CVE-2020-5250HIGHPossible information disclosure in PrestaShopEPSS 0.9%CVE-2020-5251HIGHInformation disclosure in parse-serverEPSS 0.8%CVE-2021-42336MEDIUMHuachu Digital Technology Co.,Ltd. Easytest - Improper AuthorizationEPSS 0.8%CVE-2021-28501CRITICALAn issue has recently been discovered in Arista EOS where the incorrect use of EOS's AAA API’s by the OpenConfig and TerminAttr agents could result in unrestricted access to the device for local users with nopassword configuration.EPSS 0.8%CVE-2025-30389HIGHAzure Bot Framework SDK Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2019-1859HIGHCisco Small Business Switches Secure Shell Certificate Authentication Bypass VulnerabilityEPSS 0.8%CVE-2021-22862—Improper access control in GitHub Enterprise Server leading to the disclosure of Actions secrets to forksEPSS 0.8%CVE-2024-2317LOWBdtask Hospital AutoManager Prescription Page improper authorizationEPSS 0.8%CVE-2024-21137MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.35 aEPSS 0.8%CVE-2025-1226MEDIUMywoa setup.jsp improper authorizationEPSS 0.8%CVE-2019-15610—Improper authorization in the Circles app 0.17.7 causes retaining access when an email address was removed from a circle.EPSS 0.8%