Fallos del tipo CWE-285

1604 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2019-1842MEDIUMCisco IOS XR Software Secure Shell Authentication VulnerabilityEPSS 1.2%CVE-2019-3842MEDIUMIn systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variableEPSS 1.2%CVE-2018-17933—VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) connected to the VGo XAMPP. User accounts may be able EPSS 1.2%CVE-2018-1116MEDIUMA flaw was found in polkit before version 0.116. The implementation of the polkit_backend_interactive_authority_check_authorization functionEPSS 1.2%CVE-2019-15990MEDIUMCisco Small Business Routers RV016, RV042, RV042G, and RV082 Information Disclosure VulnerabilityEPSS 1.2%CVE-2021-43847MEDIUMAuthorization Bypass in Space Invite in HumHubEPSS 1.2%CVE-2020-7530—A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to EPSS 1.2%CVE-2020-1720LOWA flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticatedEPSS 1.2%CVE-2020-5232HIGHEthereum Name Service - Malicious takeover of previously owned ENS namesEPSS 1.2%CVE-2022-20921HIGHCisco ACI Multi-Site Orchestrator Privilege Escalation VulnerabilityEPSS 1.2%CVE-2017-0894—Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting EPSS 1.2%CVE-2022-36090HIGHorg.xwiki.platform:xwiki-platform-oldcore Improper Authorization check for inactive usersEPSS 1.2%CVE-2021-31384HIGHJunos OS: SRX Series: Under a specific device configuration an attacker can access the devices J-Web management services from any interface, regardless of security settings protecting the serviceEPSS 1.2%CVE-2022-39322CRITICAL@keystone-6/core vulnerable to field-level access-control bypass for multiselect fieldEPSS 1.1%CVE-2017-2686—Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability that could allow an authenticated user to read arbitrary files through the weEPSS 1.1%CVE-2020-5275HIGHFirewall configured with unanimous strategy was not actually unanimous in symfony/security-httpEPSS 1.1%CVE-2024-27930MEDIUMSensitive fields access through dropdowns in GLPIEPSS 1.1%CVE-2021-32620HIGHUsers registered with email verification can self re-activate their disabled accountsEPSS 1.1%CVE-2020-9048HIGHvictor Web Client - Arbitrary File Deletion VulnerabilityEPSS 1.1%CVE-2020-5318HIGHDell EMC Isilon OneFS versions 8.1.2, 8.1.0.4, 8.1.0.3, and 8.0.0.7 contain a vulnerability in some configurations. An attacker may exploit EPSS 1.1%