Fallos del tipo CWE-285

1605 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2024-28285CRITICALA Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/elgamal.h of Cryptopp Crypto++ 8.9, allows an attacker to co-reEPSS 0.5%CVE-2024-23649HIGHAny authenticated user may obtain private message details from other users on the same instanceEPSS 0.5%CVE-2024-0870MEDIUMYITH WooCommerce Gift Cards <= 4.12.0 - Missing Authorization to Unauthenticated WooCommerce Settings UpdateEPSS 0.5%CVE-2026-20190HIGHCisco Identity Services Engine Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.5%CVE-2026-55065HIGHVikunja: Improper Authorization and Authorization Bypass Through User-Controlled Key in code.vikunja.io/apiEPSS 0.5%CVE-2023-3957MEDIUMACF Photo Gallery Field <= 1.9 - Authenticated (Subscriber+) Arbitrary Usermeta UpdateEPSS 0.5%CVE-2026-38533MEDIUMAn improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.EPSS 0.5%CVE-2023-0584MEDIUMVK Blocks <= 1.57.0.5 - Authenticated(Contributor+) Settings UpdateEPSS 0.5%CVE-2026-56313HIGHCapgo - Cross-Organization Account Disruption via SSO Prelink EndpointEPSS 0.5%CVE-2026-16879HIGHIBM Db2 Mirror for i is affected by multiple vulnerabilitiesEPSS 0.5%CVE-2026-46605MEDIUMApache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Incomplete authorization during destination removalEPSS 0.5%CVE-2025-54378HIGHHAX CMS Backend Lacks Comprehensive Authorization ChecksEPSS 0.5%CVE-2022-2675—Unitree Go 1 "Robot Dog" Unauthenticated Remote Power DownEPSS 0.5%CVE-2024-9235HIGHMapster WP Maps <= 1.5.0 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Options UpdateEPSS 0.5%CVE-2022-31666HIGHHarbor fails to validate user permissions while Viewing, updating and deleting Webhook policiesEPSS 0.5%CVE-2023-0734HIGHImproper Authorization in wallabag/wallabagEPSS 0.5%CVE-2019-3820MEDIUMIt was discovered that the gnome-shell lock screen since version 3.15.91 did not properly restrict all contextual actions. An attacker with EPSS 0.5%CVE-2023-34091MEDIUMKyverno resource with a deletionTimestamp may allow policy circumventionEPSS 0.5%CVE-2026-2896MEDIUMfunadmin Configuration Ajax.php setConfig improper authorizationEPSS 0.5%