Fallos del tipo CWE-287

2419 resultados

Autenticação inadequada ou ausente

A aplicação não valida ou valida de forma insuficiente a identidade de quem tenta acessá-la. Quando um usuário diz ser quem é, o sistema acredita sem verificar corretamente, permitindo que atacantes se façam passar por outros usuários ou contas legítimas.

Ejemplo

Um sistema que aceita login apenas com nome de usuário, sem senha. Ou uma API que confia no header 'User-ID' enviado pelo cliente sem validar se aquele usuário realmente existe ou tem sessão ativa. Um atacante simplesmente altera o header e acessa dados de outra conta.

Cómo mitigar

Implemente autenticação robusta: exija múltiplos fatores (senha forte + MFA), valide credenciais contra base de dados segura, use sessões com token assinado e com expiração, nunca confie em dados enviados pelo cliente como prova de identidade. Revise regularmente logs de acesso para detectar abusos.

CVE-2023-28862CRITICALAn issue was discovered in LemonLDAP::NG before 2.16.1. Weak session ID generation in the AuthBasic handler and incorrect failure handling dEPSS 1.0%CVE-2022-47633HIGHAn image signature validation bypass vulnerability in Kyverno 1.8.3 and 1.8.4 allows a malicious image registry (or a man-in-the-middle attaEPSS 1.0%CVE-2021-4230LOWAirfield Online MySQL Backup improper authenticationEPSS 1.0%CVE-2022-4002HIGHA command injection vulnerability could allow an authenticated user to execute operating system commands as root via a specially crafted APIEPSS 1.0%CVE-2021-28174MEDIUMMitake Smart Stock Selection System - Broken AuthenticationEPSS 1.0%CVE-2014-125060HIGHholdennb CollabCal calenderServer.cpp handleGet improper authenticationEPSS 1.0%CVE-2021-26077CRITICALBroken Authentication in Atlassian Connect Spring Boot (ACSB) in version 1.1.0 before 2.1.3 and from version 2.1.4 before 2.1.5: Atlassian CEPSS 1.0%CVE-2026-76187CRITICALApache Airflow Keycloak provider: Any realm client's credentials mint an Airflow session JWTEPSS 0.9%CVE-2022-36106MEDIUMMissing check for expiration time of password reset token in TYPO3EPSS 0.9%CVE-2020-26236HIGHVerification Code Hijacking in ScratchVerifierEPSS 0.9%CVE-2022-22730CRITICALImproper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to poteEPSS 0.9%CVE-2025-5495MEDIUMNetgear WNR614 URL improper authenticationEPSS 0.9%CVE-2021-32951MEDIUMAdvantech WebAccess/NMS Improper AuthenticationEPSS 0.9%CVE-2023-22303CRITICALTP-Link SG105PE firmware prior to 'TL-SG105PE(UN) 1.0_1.0.0 Build 20221208' contains an authentication bypass vulnerability. Under the certaEPSS 0.9%CVE-2023-31127CRITICALDMTF-2023-0001: SPDM mutual authentication bypassEPSS 0.9%CVE-2023-6344MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server te003.aspx and te004.aspx allows authentication bypassEPSS 0.9%CVE-2023-6343MEDIUMTyler Technologies Court Case Management Plus use of Aquaforest TIFF Server tssp.aspx allows authentication bypassEPSS 0.9%CVE-2018-7340HIGHMultiple SAML libraries may allow authentication bypass via incorrect XML canonicalization and DOM traversalEPSS 0.9%CVE-2021-28495HIGHIn Arista's MOS (Metamako Operating System) software which is supported on the 7130 product line, under certain conditions, user authenticatEPSS 0.9%CVE-2026-78168CRITICALEFM ipTIME T24000M Session Validation httpcon_check_session_url improper authenticationEPSS 0.9%