Fallos del tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

É quando o software aceita dados sem validar adequadamente se vieram de uma fonte legítima e confiável. O sistema confia em informações (mensagens, arquivos, requisições) sem confirmar sua origem ou integridade, permitindo que um atacante forje, modifique ou injete dados maliciosos que serão processados como se fossem legítimos.

Ejemplo

Um serviço aceita atualizações de configuração via JSON sem verificar assinatura digital ou token HMAC. Um atacante intercepta a requisição e modifica o payload para redirecionar logs para um servidor controlado por ele — e o serviço aplica a mudança porque 'recebeu um JSON válido'.

Cómo mitigar

Implemente autenticação criptográfica de dados: use assinatura digital (HMAC, RSA, ECDSA) ou tokens com validade (JWT com chave secreta), valide sempre a origem da mensagem antes de processar, e recuse dados sem prova de autenticidade. Não confie apenas em formato válido ou canal de transporte — valide origem e integridade.

CVE-2026-15150MEDIUMmyCred < 3.2.5 - Unauthenticated Payment Bypass via Missing PayPal IPN Receiver Verification in buyCREDEPSS 0.1%CVE-2026-15147MEDIUMFive Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOREPSS 0.1%CVE-2026-12901MEDIUMGetPaid < 2.8.55 - Unauthenticated Worldpay Payment Bypass via Insufficient IPN VerificationEPSS 0.1%CVE-2026-15208MEDIUMRegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal VerificationEPSS 0.1%CVE-2026-44523CRITICALNote Mark: JWT Secret Weakness allows Full Account Takeover via token forgeryEPSS 0.1%CVE-2026-88819MEDIUMIn Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.EPSS 0.1%CVE-2026-84767MEDIUMWordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerabilityEPSS 0.1%CVE-2022-0031MEDIUMCortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR EngineEPSS 0.1%CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.1%CVE-2022-2789MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, aEPSS 0.1%CVE-2026-68945HIGHAngular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State PoisoningEPSS 0.1%CVE-2021-26403MEDIUMInsufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confideEPSS 0.1%CVE-2026-47696HIGHWWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpointEPSS 0.1%CVE-2026-17011LOWNexter Blocks < 5.0.2 - Contributor+ Stored CSS InjectionEPSS 0.1%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.1%CVE-2026-85008LOWundici vulnerable to caching and replay of unsafe HTTP method responsesEPSS 0.1%CVE-2026-30603MEDIUMAn issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, aEPSS 0.1%CVE-2022-33861MEDIUMInsufficient verification of authenticity in IPPEPSS 0.1%CVE-2026-35659MEDIUMOpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD DiscoveryEPSS 0.1%CVE-2022-42267HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code EPSS 0.1%