Fallos del tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

É quando o software aceita dados sem validar adequadamente se vieram de uma fonte legítima e confiável. O sistema confia em informações (mensagens, arquivos, requisições) sem confirmar sua origem ou integridade, permitindo que um atacante forje, modifique ou injete dados maliciosos que serão processados como se fossem legítimos.

Ejemplo

Um serviço aceita atualizações de configuração via JSON sem verificar assinatura digital ou token HMAC. Um atacante intercepta a requisição e modifica o payload para redirecionar logs para um servidor controlado por ele — e o serviço aplica a mudança porque 'recebeu um JSON válido'.

Cómo mitigar

Implemente autenticação criptográfica de dados: use assinatura digital (HMAC, RSA, ECDSA) ou tokens com validade (JWT com chave secreta), valide sempre a origem da mensagem antes de processar, e recuse dados sem prova de autenticidade. Não confie apenas em formato válido ou canal de transporte — valide origem e integridade.

CVE-2024-25584MEDIUMDovecot accepts dot LF DOT LF symbol as end of DATA command. RFC requires that it should always be CR LF DOT CR LF. This causes Dovecot to cEPSS 0.2%CVE-2025-24903HIGHlibsignal-service-rs Doesn't Check Origin of Sync MessagesEPSS 0.2%CVE-2025-66016CRITICALCGGMP24 is missing a check in the ZK proof used in CGGMP21EPSS 0.2%CVE-2026-82549MEDIUMLinux Foundation Magma SecurityModeComplete integrity checkEPSS 0.2%CVE-2024-7847HIGHRSLogix™ 5 and RSLogix 500® Remote Code Execution Via VBA Embedded ScriptEPSS 0.2%CVE-2025-59700MEDIUMEntrust nShield Connect XC, nShield 5c, and nShield HSMi through 13.6.11, or 13.7 (patched in 13.6.12 (LTS) and 13.9.0 (STS)), allow a physiEPSS 0.2%CVE-2026-6498MEDIUMFive Star Restaurant Reservations <= 2.7.16 - Unauthenticated Payment Bypass via PHP Type Juggling in 'payment_id' ParameterEPSS 0.2%CVE-2024-55929MEDIUMMail spoofingEPSS 0.2%CVE-2025-15598MEDIUMDataease SQLBot JWT Token auth.py validateEmbedded signature verificationEPSS 0.2%CVE-2026-54167HIGHPipelines-as-Code GitHub App token request can be redirected via untrusted Enterprise Host headerEPSS 0.2%CVE-2026-32231HIGHZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is checked against untrusted payload dataEPSS 0.2%CVE-2023-52546HIGHVulnerability of package name verification being bypassed in the Calendar app. Impact: Successful exploitation of this vulnerability may affEPSS 0.2%CVE-2022-28757HIGHLocal Privilege Escalation in Auto Updater for Zoom Client for Meetings for macOSEPSS 0.2%CVE-2026-86039HIGHlibp2p: PeerStore accepts attacker-signed PeerRecords for a victim peer ID and stores certified attacker addressesEPSS 0.2%CVE-2026-76245HIGHstigmem Federation Peer Token Timestamp Validation BypassEPSS 0.2%CVE-2019-16000MEDIUMCisco Umbrella Roaming Client for Windows Install VulnerabilityEPSS 0.2%CVE-2026-15615HIGHSAML <Conditions> element not validatedEPSS 0.2%CVE-2026-15612CRITICALLOIDC nonce validation bypassEPSS 0.2%CVE-2026-33143HIGHOneUptime: WhatsApp Webhook Missing Signature VerificationEPSS 0.2%CVE-2026-85429HIGHMOOS-IvP through 24.8.1 uFldNodeComms Node Message Source SpoofingEPSS 0.2%