Fallos del tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

É quando o software aceita dados sem validar adequadamente se vieram de uma fonte legítima e confiável. O sistema confia em informações (mensagens, arquivos, requisições) sem confirmar sua origem ou integridade, permitindo que um atacante forje, modifique ou injete dados maliciosos que serão processados como se fossem legítimos.

Ejemplo

Um serviço aceita atualizações de configuração via JSON sem verificar assinatura digital ou token HMAC. Um atacante intercepta a requisição e modifica o payload para redirecionar logs para um servidor controlado por ele — e o serviço aplica a mudança porque 'recebeu um JSON válido'.

Cómo mitigar

Implemente autenticação criptográfica de dados: use assinatura digital (HMAC, RSA, ECDSA) ou tokens com validade (JWT com chave secreta), valide sempre a origem da mensagem antes de processar, e recuse dados sem prova de autenticidade. Não confie apenas em formato válido ou canal de transporte — valide origem e integridade.

CVE-2024-48916HIGHCeph is vulnerable to authentication bypass through RadosGWEPSS 0.2%CVE-2026-40323HIGHSP1 V6 Recursion Circuit Row-Count Binding GapEPSS 0.2%CVE-2026-63127HIGHRMCP: Missing Resource Field Validation in OAuth Protected Resource Metadata DiscoveryEPSS 0.2%CVE-2024-47079MEDIUMUnauthorized usage of remote hardware module because of missing channel verificationEPSS 0.2%CVE-2026-67307HIGHWazuh before 5.0.0-beta3 Cluster Attribution Spoofing via Inventory SyncEPSS 0.2%CVE-2024-33687HIGHInsufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a useEPSS 0.2%CVE-2023-49087MEDIUMValidation of SignedInfoEPSS 0.2%CVE-2026-73419MEDIUMNextAuth.js: OAuth state, nonce, and PKCE check cookies are not bound to the provider that created themEPSS 0.2%CVE-2026-54783HIGHCoreWCF: XML Signature Wrapping in WS-Security endorsing/supporting signature verification allows replay of captured signed messagesEPSS 0.2%CVE-2026-59930MEDIUMMistune toc / TableOfContents directive: heading IDs use predictable `toc_N` numbering with no slugification, allowing collision with attacker-controlled `id="toc_N"` contentEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2026-43534CRITICALOpenClaw < 2026.4.10 - Unsanitized External Input in Agent Hook EventsEPSS 0.2%CVE-2026-32029MEDIUMOpenClaw < 2026.2.21 - Client IP Spoofing via X-Forwarded-For Header ParsingEPSS 0.2%CVE-2021-41203HIGHMissing validation during checkpoint loadingEPSS 0.2%CVE-2024-5684MEDIUMID Charger Connect & Pro - JWT-Null-AlgorithmEPSS 0.2%CVE-2026-82858CRITICAL@hulumi/drift before 1.3.2 Unsafe Execute Plan AcceptanceEPSS 0.2%CVE-2026-19941MEDIUMcheckwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proofEPSS 0.2%CVE-2026-3446MEDIUMBase64 decoding stops at first padded quad by defaultEPSS 0.2%CVE-2026-34061MEDIUMnimiq/core-rs-albatross: Macro block proposal interlink bugEPSS 0.2%