Fallos del tipo CWE-552

365 resultados

Arquivos ou diretórios acessíveis a partes externas

Ocorre quando arquivos ou diretórios sensíveis são deixados com permissões inadequadas, permitindo que usuários não autorizados (locais ou remotos) leiam, modifiquem ou executem conteúdo que deveria estar protegido. O erro típico é confiar em permissões padrão do sistema ou definir chmod/ACL incorretamente, expondo dados críticos como credenciais, configurações ou código.

Ejemplo

Um aplicativo salva chaves SSH ou tokens de API em ~/.ssh/config ou /etc/app/secrets.conf com permissão 644 (legível por qualquer usuário), ou um servidor web expõe um diretório de backup (.bak, .sql) sem autenticação. Um atacante local ou remoto consegue acessar diretamente esses arquivos e comprometer a segurança.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask correto, chmod 600 para arquivos sensíveis, 700 para diretórios) e use ACLs/SELinux quando necessário. Valide permissões em testes, esconda backups e arquivos temporários fora do diretório web, e implemente verificações de acesso no código antes de servir qualquer recurso.

CVE-2021-4112—A flaw was found in ansible-tower where the default installation is vulnerable to job isolation escape. This flaw allows an attacker to elevEPSS 0.2%CVE-2024-38876HIGHA vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All verEPSS 0.2%CVE-2025-25799MEDIUMSeaCMS 13.3 was discovered to contain an arbitrary file read vulnerability in the file_get_contents function at admin_safe.php.EPSS 0.2%CVE-2023-2538MEDIUMTLS Private Key Accessible to External PartiesEPSS 0.2%CVE-2025-31996MEDIUMUnprotected files are impacting HCL Unica PlatformEPSS 0.2%CVE-2024-35183MEDIUMwolfictl leaks GitHub tokens to remote non-GitHub git serversEPSS 0.2%CVE-2024-23282MEDIUMThe issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14EPSS 0.2%CVE-2026-74853MEDIUMPods < 3.3.9.2 - Author+ Arbitrary File Read via Shortcode Display CallbackEPSS 0.2%CVE-2025-33150MEDIUMIBM Cognos Analytics Certified Containers information disclosureEPSS 0.2%CVE-2022-42834LOWAn access issue was addressed with improved access restrictions. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13, macOS Big SEPSS 0.2%CVE-2026-35446HIGHLORIS has a path traversal in FilesDownloadHandlerEPSS 0.2%CVE-2021-1434MEDIUMCisco IOS XE SD-WAN Software Arbitrary File Corruption VulnerabilityEPSS 0.2%CVE-2021-1512MEDIUMCisco SD-WAN Software Arbitrary File Corruption VulnerabilityEPSS 0.2%CVE-2025-23421MEDIUMQardio iOS and Android applications Files or Directories Accessible to External PartiesEPSS 0.2%CVE-2026-75889HIGHCVE-2026-75889 CVE RecordEPSS 0.2%CVE-2026-7817HIGHpgAdmin 4: Local file inclusion and server-side request forgery in LLM API configuration endpointsEPSS 0.2%CVE-2025-4134HIGHLack of file validation in Avast Business Antivirus for Linux allows writing untrusted update filesEPSS 0.2%CVE-2026-88623HIGHNUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the user via POST is receiEPSS 0.2%CVE-2023-20039MEDIUMCisco Industrial Network Director File PermissionsEPSS 0.2%CVE-2023-31017HIGHCVEEPSS 0.2%