Fallos del tipo CWE-304

41 resultados

Autenticação incompleta ou com etapas puladas

A aplicação implementa um mecanismo de autenticação, mas omite ou pula uma ou mais etapas críticas do fluxo, enfraquecendo a segurança. Isso permite que um atacante contorne a autenticação ou escalpe privilégios sem completar todas as verificações necessárias.

Ejemplo

Um sistema que deveria exigir MFA (autenticação multifator) permite login apenas com senha se o usuário acessar de um IP previamente registrado, pulando a segunda etapa. Ou uma API que valida token JWT mas não verifica a expiração, deixando tokens revogados ainda válidos.

Cómo mitigar

Implemente todas as etapas do fluxo de autenticação sem exceções ou atalhos. Realize testes de segurança (incluindo testes negativos) para garantir que nenhuma condição permite bypasses, e mantenha a autenticação estrita mesmo em cenários 'confiáveis'.

CVE-2024-45764CRITICALDell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated atEPSS 0.5%CVE-2026-61466CRITICALApache CXF: OAuth2 Dynamic Client Registration Scope Self-EscalationEPSS 0.4%CVE-2026-49467HIGHTOTP enrollment hijack: password gate skipped due to unawaited promiseEPSS 0.4%CVE-2023-22833HIGHMandatory control bypass in Lime2EPSS 0.4%CVE-2026-67351HIGHSerendipity < 2.6.1 Authentication Bypass via Username CollisionEPSS 0.4%CVE-2024-7745MEDIUMMulti-Factor Authentication Bypass in Progress WS_FTP ServerEPSS 0.4%CVE-2026-30831HIGHRocket.Chat: 2FA bypass and login of deactivated users via EE ddp-streamerEPSS 0.3%CVE-2024-20153HIGHIn wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosuEPSS 0.3%CVE-2026-54723MEDIUMdevpi: Database contents leakEPSS 0.3%CVE-2026-61143MEDIUMVulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported EPSS 0.3%CVE-2025-55138HIGHLinkJoin through 882f196 mishandles token ownership in password reset.EPSS 0.3%CVE-2026-42452HIGHTermix: Pending-TOTP temporary token can regenerate backup codes and neutralize TOTPEPSS 0.3%CVE-2026-59564CRITICALAuthentication bypass between ZCC and client connector portalEPSS 0.3%CVE-2025-5715LOWSignal App Biometric Authentication missing critical step in authenticationEPSS 0.3%CVE-2024-52965MEDIUMA missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.EPSS 0.3%CVE-2026-76207HIGHphpMyFAQ before 4.1.7 2FA Bypass via Remember-Me CookieEPSS 0.3%CVE-2024-11302HIGHMissing check_access in lollms_binding_infos in parisneo/lollmsEPSS 0.2%CVE-2025-43014MEDIUMIn JetBrains Toolbox App before 2.6 the SSH plugin established connections without sufficient user confirmationEPSS 0.2%CVE-2026-44547CRITICALChurchCRM: Incomplete fix for CVE-2026-40582: public API login still bypasses 2FA and account lockout in ChurchCRM 7.2.2EPSS 0.2%CVE-2025-43798LOWLiferay DXP 2023.Q4.0, 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92 and 7.3 GA through update 35 allows a time-based one-time passwEPSS 0.2%