Fallos del tipo CWE-350

33 resultados

Confiança em resolução DNS reversa para ações críticas de segurança

A aplicação usa reverse DNS (consulta de nome a partir de um IP) como mecanismo de autenticação ou autorização, assumindo que o resultado é confiável. Isso é perigoso porque um atacante pode controlar ou falsificar respostas DNS, permitindo contornar verificações de segurança ou acessar recursos restritos.

Ejemplo

Um servidor de backup rejeita conexões verificando se o IP reverso resolve para um hostname autorizado (ex: 'backup.exemplo.com'). Um atacante controla o servidor DNS e faz o próprio IP reverso resolver para esse hostname, ganhando acesso não autorizado.

Cómo mitigar

Sempre validar identidades com mecanismos criptográficos (certificados TLS, tokens assinados, autenticação mútua) em vez de confiar em DNS. Se reverse DNS for necessário por compatibilidade, usar apenas como complemento informativo, nunca como único fator de decisão de segurança.

CVE-2021-22884Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “lEPSS 32.4%CVE-2018-7160The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. AEPSS 9.9%CVE-2017-0902RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client EPSS 4.8%CVE-2026-1490CRITICALSpam protection, Honeypot, Anti-Spam by CleanTalk <= 6.71 - Authorization Bypass via Reverse DNS (PTR record) Spoofing to Unauthenticated Arbitrary Plugin InstallationEPSS 1.2%CVE-2021-34561HIGHA vulnerability in WirelessHART-Gateway <= 3.0.8 allows to bypass any IP or firewall based access restrictions through DNS rebindingEPSS 0.9%CVE-2020-11091MEDIUMWeave Net clusters susceptible to MitM attacks via IPv6 rogue router advertisementsEPSS 0.9%CVE-2023-32020MEDIUMWindows DNS Spoofing VulnerabilityEPSS 0.7%CVE-2026-24281MEDIUMApache ZooKeeper: Reverse-DNS fallback enables hostname verification bypass in ZooKeeper ZKTrustManagerEPSS 0.6%CVE-2022-22364MEDIUMIBM Cognos Controller security bypassEPSS 0.5%CVE-2023-52235HIGHSpaceX Starlink Wi-Fi router GEN 2 before 2023.53.0 and Starlink Dish before 07dd2798-ff15-4722-a9ee-de28928aed34 allow CSRF (e.g., for a reEPSS 0.5%CVE-2026-57123CRITICALPraisonAI: MCP SSE transport binds 0.0.0.0 with no authentication and no Origin validation; bundled SecurityConfig is never wired inEPSS 0.5%CVE-2026-75514MEDIUMBunkerWeb: rDNS bypass via missing forward-confirmation (FCrDNS) in blacklist, greylist, and antibotEPSS 0.5%CVE-2026-28271MEDIUMKiteworks Core is vulnerable to Server-Side Request Forgery (SSRF)EPSS 0.4%CVE-2025-59956MEDIUMAgentAPI exposed user chat history via a DNS rebinding attackEPSS 0.4%CVE-2025-8036HIGHDNS rebinding circumvents CORSEPSS 0.4%CVE-2025-59163LOWvet MCP Server SSE Transport DNS Rebinding VulnerabilityEPSS 0.4%CVE-2026-61568CRITICAL@zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transportEPSS 0.3%CVE-2025-24010MEDIUMVite allows any websites to send any requests to the development server and read the responseEPSS 0.3%CVE-2026-53708MEDIUMContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)EPSS 0.3%CVE-2026-33002HIGHJenkins 2.442 through 2.554 (both inclusive), LTS 2.426.3 through LTS 2.541.2 (both inclusive) performs origin validation of requests made tEPSS 0.3%