Fallos del tipo CWE-285

1604 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2021-21362HIGHBypassing readOnly policy by creating a temporary 'mc share upload' URLEPSS 1.3%CVE-2022-2595CRITICALImproper Authorization in kromitgmbh/titraEPSS 1.3%CVE-2019-10154MEDIUMA flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversationEPSS 1.3%CVE-2021-22865—Improper access control in GitHub Enterprise Server leading to unauthorized read access to private repository metadataEPSS 1.3%CVE-2025-1361HIGHIP2Location Country Blocker <= 2.38.8 - Missing Authorization to Unauthenticated Information Exposure via admin_init FunctionEPSS 1.3%CVE-2021-24191—WP Maintenance Mode & Site Under Construction < 1.8.2 - Arbitrary Plugin Installation/Activation via Low Privilege UserEPSS 1.3%CVE-2022-0829MEDIUMImproper Authorization in webmin/webminEPSS 1.3%CVE-2020-5206HIGHAuthentication Bypass For Endpoints With Anonymous Access in OpenCastEPSS 1.3%CVE-2019-6581—A vulnerability has been identified in Siveillance VMS 2017 R2 (All versions < V11.2a), Siveillance VMS 2018 R1 (All versions < V12.1a), SivEPSS 1.3%CVE-2021-41137HIGHBypassing policy restrictions on regular usersEPSS 1.3%CVE-2020-14486MEDIUMOpenClinic GAEPSS 1.3%CVE-2017-0896—Zulip Server 1.5.1 and below suffer from an error in the implementation of the invite_by_admins_only setting in the Zulip group chat applicaEPSS 1.3%CVE-2020-5356HIGHDell PowerProtect Data Manager (PPDM) versions prior to 19.4 and Dell PowerProtect X400 versions prior to 3.2 contain an improper authorizatEPSS 1.3%CVE-2019-3785MEDIUMCloud Controller provides signed URL with write authorization to read only userEPSS 1.3%CVE-2024-38129HIGHWindows Kerberos Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2021-41974CRITICALTad Book3 - Improper AuthorizationEPSS 1.3%CVE-2020-5289MEDIUMRead permissions not enforced for client provided filter expressions in Elide http clientEPSS 1.3%CVE-2019-2386HIGHAuthorization session conflationEPSS 1.2%CVE-2026-43515CRITICALApache Tomcat: Security constraints not correctly appliedEPSS 1.2%CVE-2020-10620—Opto 22 SoftPAC Project Version 9.6 and prior. SoftPAC communication does not include any credentials. This allows an attacker with network EPSS 1.2%