Fallos del tipo CWE-290

607 resultados

Autenticação inadequada sujeita a falsificação de identidade

Ocorre quando o mecanismo de autenticação é implementado de forma fraca ou incompleta, permitindo que um atacante se faça passar por outro usuário ou sistema sem precisar das credenciais legítimas. O risco é grave: qualquer um pode ganhar acesso não autorizado simplesmente contornando ou falsificando a identidade.

Ejemplo

Um app que autentica usuários apenas verificando um header HTTP customizado (tipo 'X-User-ID: 123') sem validação criptográfica real. Um atacante muda esse header para 'X-User-ID: admin' e consegue acesso à conta administrativa. Ou um serviço que aceita requisições apenas porque vêm de um IP específico, sem verificar certificados ou assinaturas.

Cómo mitigar

Use protocolos de autenticação estabelecidos (OAuth 2.0, JWT com assinatura, SAML) em vez de inventar o seu. Sempre valide credenciais no servidor com mecanismos criptográficos (hash, assinatura digital, certificados). Nunca confie em headers HTTP, IPs ou tokens não assinados como prova única de identidade.

CVE-2024-36557MEDIUMThe device ID is based on IMEI in Forever KidsWatch Call Me KW50 R36_YDR_A3PW_GM7S_V1.0_2019_07_15_16.19.24_cob_h and Forever KidsWatch CallEPSS 0.2%CVE-2025-13636MEDIUMInappropriate implementation in Split View in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who convinced a user to engage EPSS 0.2%CVE-2026-32014HIGHOpenClaw < 2026.2.26 - Node Reconnect Metadata Spoofing via Unsigned Platform FieldsEPSS 0.2%CVE-2024-27853MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.4. A maliciously crafted ZIP archive may bypass GatekeEPSS 0.2%CVE-2023-6044MEDIUMA privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate LeEPSS 0.2%CVE-2026-11870MEDIUMHide My WP Ghost < 7.0.05 - IP Address Spoofing via Trusted Proxy Headers Leading to Protection Mechanism BypassEPSS 0.2%CVE-2026-90711CRITICALproxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnetEPSS 0.2%CVE-2025-36754CRITICALAuthentication bypass on web interfaceEPSS 0.2%CVE-2026-86039HIGHlibp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addressesEPSS 0.2%CVE-2026-27478CRITICALUnity Catalog has a JWT Issuer Validation Bypass Allows Complete User ImpersonationEPSS 0.2%CVE-2026-67558HIGHMira Hormone Monitor, Mira Android App Authentication bypass by spoofingEPSS 0.2%CVE-2026-11922MEDIUMRate-limit Bypass in zenml-io/zenmlEPSS 0.2%CVE-2026-53833HIGHQQBot for OpenClaw < 2026.4.29 - Authorization Bypass via QQBot Streaming CommandEPSS 0.2%CVE-2026-54478LOWDNS Cookie bypass when combined with proxy-protocol useEPSS 0.2%CVE-2026-7422HIGHMAC Address Validation Bypass in FreeRTOS-Plus-TCP IPv4 and IPv6 Packet ProcessingEPSS 0.2%CVE-2025-7448HIGHMan in the middle (MitM) attack vulnerability in Wi-SUN libraryEPSS 0.2%CVE-2026-47845MEDIUMReactor Netty HTTP Server may incorrectly evaluate proxy addressesEPSS 0.2%CVE-2026-39309MEDIUMTrilium Notes: macOS TCC Bypass via Prompt SpoofingEPSS 0.2%CVE-2026-85511MEDIUMWildfly-elytron-realm-token: parameter injection in eap's elytron oauth2EPSS 0.2%CVE-2026-84849MEDIUMWordPress Pre-Orders for WooCommerce plugin <= 2.3 - Bypass Vulnerability vulnerabilityEPSS 0.2%