Fallos del tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

É quando o software aceita dados sem validar adequadamente se vieram de uma fonte legítima e confiável. O sistema confia em informações (mensagens, arquivos, requisições) sem confirmar sua origem ou integridade, permitindo que um atacante forje, modifique ou injete dados maliciosos que serão processados como se fossem legítimos.

Ejemplo

Um serviço aceita atualizações de configuração via JSON sem verificar assinatura digital ou token HMAC. Um atacante intercepta a requisição e modifica o payload para redirecionar logs para um servidor controlado por ele — e o serviço aplica a mudança porque 'recebeu um JSON válido'.

Cómo mitigar

Implemente autenticação criptográfica de dados: use assinatura digital (HMAC, RSA, ECDSA) ou tokens com validade (JWT com chave secreta), valide sempre a origem da mensagem antes de processar, e recuse dados sem prova de autenticidade. Não confie apenas em formato válido ou canal de transporte — valide origem e integridade.

CVE-2026-58002HIGHWWBN AVideo Authorization Bypass via Users_affiliations add.json.phpEPSS 0.1%CVE-2026-39969MEDIUMTypeBot: WhatsApp Webhook Endpoint Missing Signature VerificationEPSS 0.1%CVE-2025-23415LOWBIG-IP APM Endpoint Inspection vulnerabilityEPSS 0.1%CVE-2026-54579LOWmport mirror-selection ping accepts insufficiently validated ICMP repliesEPSS 0.1%CVE-2026-81702CRITICALopenssl_encrypt before 1.4.9 Key Substitution via Identity LoadEPSS 0.1%CVE-2026-2428HIGHFluent Forms Pro Add On Pack <= 6.1.17 - Missing Authorization to Unauthenticated Payment Status modificationEPSS 0.1%CVE-2026-71858MEDIUMNotepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command ExecutionEPSS 0.1%CVE-2022-22567MEDIUMSelect Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An aEPSS 0.1%CVE-2026-53728HIGHMedplum - Improper Validation of Redirect URI in External Auth Callback allows Authorization Code LeakageEPSS 0.1%CVE-2026-10079HIGHStackrox: stackrox: deploy-time policy enforcement and visibility bypass via label injectionEPSS 0.1%CVE-2023-36858HIGHBIG-IP Edge Client for Windows and macOS vulnerabilityEPSS 0.1%CVE-2026-54586MEDIUMmport permits repository and package mirror fetches over insecure transportEPSS 0.1%CVE-2026-85641MEDIUMFormidable Forms 6.34 - Unauthenticated Stored Content Injection via 'updated_by' ParameterEPSS 0.1%CVE-2026-82462MEDIUMpac4j-oidc before 6.5.6 Authentication Bypass via Access Token SubstitutionEPSS 0.1%CVE-2026-81706CRITICALopenssl_encrypt before 1.4.9 Key Substitution via Identity ShadowingEPSS 0.1%CVE-2026-73450HIGHSecurity Advisory 0161EPSS 0.1%CVE-2024-39805HIGHInsufficient verification of data authenticity in some Intel(R) DSA software before version 23.4.39 may allow an authenticated user to potenEPSS 0.1%CVE-2025-56438MEDIUMAn issue in the firmware update mechanism of Nous W3 Smart WiFi Camera v1.33.50.82 allows unauthenticated and physically proximate attackersEPSS 0.1%CVE-2023-43636HIGHRootfs Not ProtectedEPSS 0.1%CVE-2026-49331MEDIUMOpenshift/oauth-proxy: openshift/oauth-proxy: unauthenticated identity header injection on whitelisted pathsEPSS 0.1%