Fallos del tipo CWE-488

42 resultados

Exposição de dados a sessão incorreta

Uma fraqueza onde dados sensíveis de um usuário são acessíveis por outro usuário através de uma sessão diferente, geralmente porque a aplicação não isolou corretamente o escopo dos dados por sessão. O atacante consegue ler ou manipular informações que não deveria ter acesso.

Ejemplo

Um e-commerce armazena o carrinho de compras em cache global sem vincular à sessão do usuário. Quando dois clientes acessam quase simultaneamente, o segundo vê os itens do carrinho do primeiro, incluindo endereço de entrega e método de pagamento.

Cómo mitigar

Sempre associar dados de usuário a identificadores únicos de sessão (session ID, JWT com sub claim, etc) e validar essa associação antes de qualquer acesso. Usar variáveis de sessão isoladas, não globais ou de escopo amplo, e limpar dados ao fim de cada sessão.

CVE-2026-14621LOWFederatedAI FATE OSX Broker QueuePushReqStreamObserver.java QueuePushReqStreamObserver.initEggroll wrong sessionEPSS 0.4%CVE-2025-30073HIGHAn issue was discovered in OPC cardsystems Webapp Aufwertung 2.1.0. The reference assigned to transactions can be reused. When completing a EPSS 0.4%CVE-2024-8314MEDIUMImproper session handling in B&R APROLEPSS 0.4%CVE-2026-16326CRITICALconsul-mcp-server vulnerable to cross-tenant credential reuse in streamable-HTTP stateless modeEPSS 0.3%CVE-2026-46416MEDIUMMicrosoft UFO shared WebSocket handler state causes cross-client response hijackingEPSS 0.3%CVE-2026-18489HIGHIBM ContextForge Translate is affected by cross-client credential context confusionEPSS 0.3%CVE-2026-54497MEDIUMview_component: Reused Component Instances Retain Stale Render ContextEPSS 0.2%CVE-2026-82367LOWRe-entrant synchronous publish in AshGraphql subscription batcher delivers one subscriber's records to another's topicEPSS 0.2%CVE-2026-23919HIGHInsufficient isolation of JavaScript (Duktape) execution context on Zabbix ServerEPSS 0.2%CVE-2026-33215MEDIUMNATS is vulnerable to MQTT hijacking via Client IDEPSS 0.2%CVE-2026-88017HIGHrclone: FTP cross-session auth-proxy backend confusionEPSS 0.2%CVE-2026-23844MEDIUMWhisper Money has IDOR Vulnerability on sync/balances endpointEPSS 0.2%CVE-2025-24934MEDIUMSO_REUSEPORT_LB breaks connect(2) for UDP socketsEPSS 0.2%CVE-2025-2312MEDIUMcifs.upcall makes an upcall to the wrong namespace in containerized environmentsEPSS 0.2%CVE-2022-40210MEDIUMExposure of data element to wrong session in the Intel DCM software before version 5.0.1 may allow an authenticated user to potentially enabEPSS 0.2%CVE-2025-27606MEDIUMElement Android PIN autologout bypassEPSS 0.2%CVE-2026-84685MEDIUMImproper Cache Isolation in auth0/react-native-auth0 SDK Web Platform Credential ManagementEPSS 0.2%CVE-2026-27492MEDIUMLettermint Node.js SDK leaks email properties to unintended recipients when client instance is reusedEPSS 0.2%CVE-2026-9831MEDIUMExtremeCloud IQ Cross Tenant Data Exposure via Extreme Platform One Authentication Race ConditionEPSS 0.2%CVE-2026-71850MEDIUMHono: `memo()` retains SSR output across requests, leading to cross-user data disclosureEPSS 0.2%