Fallos del tipo CWE-285

1604 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2017-0926—Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthoriEPSS 1.4%CVE-2021-3044CRITICALCortex XSOAR: Unauthorized Usage of the REST APIEPSS 1.4%CVE-2022-2536MEDIUMTransposh WordPress Translation <= 1.0.9.6 - Authorization BypassEPSS 1.4%CVE-2017-2689—Siemens RUGGEDCOM ROX I (all versions) allow an authenticated user to bypass access restrictions in the web interface at port 10000/TCP to oEPSS 1.4%CVE-2024-30061HIGHMicrosoft Dynamics 365 (On-Premises) Information Disclosure VulnerabilityEPSS 1.4%CVE-2019-1907HIGHCisco Integrated Management Controller Substring Comparison Privilege Escalation VulnerabilityEPSS 1.4%CVE-2016-7077MEDIUMforeman before 1.14.0 is vulnerable to an information leak. It was found that Foreman form helper does not authorize options for associated EPSS 1.4%CVE-2016-7078MEDIUMforeman before version 1.15.0 is vulnerable to an information leak through organizations and locations feature. When a user is assigned _no_EPSS 1.4%CVE-2017-16773MEDIUMImproper authorization vulnerability in Highlight Preview in Synology Universal Search before 1.0.5-0135 allows remote authenticated users tEPSS 1.4%CVE-2021-41975HIGHTad TadTools - Improper AuthorizationEPSS 1.3%CVE-2025-66301HIGHGrav ihas Broken Access Control which allows an Editor to modify the page's YAML Frontmatter to alter form processing actionsEPSS 1.3%CVE-2021-28626LOWAdobe Experience Manager Improper Authorization at /content/usergeneratedEPSS 1.3%CVE-2021-34434—In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a EPSS 1.3%CVE-2021-24190—WooCommerce Conditional Marketing Mailer < 1.5.2 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24192—Tree Sitemap < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24193—Visitor Traffic Real Time Statistics < 2.12 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24188—WP Content Copy Protection & No Right Click < 3.1.5 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24194—Login Protection - Limit Failed Login Attempts < 2.9 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24195—Login as User or Customer (User Switching) < 1.9 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2021-24189—Captchinoo, Google recaptcha for admin login page < 2.4 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%