Fallos del tipo CWE-552

365 resultados

Arquivos ou diretórios acessíveis a partes externas

Ocorre quando arquivos ou diretórios sensíveis são deixados com permissões inadequadas, permitindo que usuários não autorizados (locais ou remotos) leiam, modifiquem ou executem conteúdo que deveria estar protegido. O erro típico é confiar em permissões padrão do sistema ou definir chmod/ACL incorretamente, expondo dados críticos como credenciais, configurações ou código.

Ejemplo

Um aplicativo salva chaves SSH ou tokens de API em ~/.ssh/config ou /etc/app/secrets.conf com permissão 644 (legível por qualquer usuário), ou um servidor web expõe um diretório de backup (.bak, .sql) sem autenticação. Um atacante local ou remoto consegue acessar diretamente esses arquivos e comprometer a segurança.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask correto, chmod 600 para arquivos sensíveis, 700 para diretórios) e use ACLs/SELinux quando necessário. Valide permissões em testes, esconda backups e arquivos temporários fora do diretório web, e implemente verificações de acesso no código antes de servir qualquer recurso.

CVE-2022-44356HIGHWAVLINK Quantum D4G (WL-WN531G3) running firmware versions M31G3.V5030.201204 and M31G3.V5030.200325 has an access control issue which allowEPSS 2.8%CVE-2018-10869HIGHredhat-certification does not properly restrict files that can be download through the /download page. A remote attacker may download any fiEPSS 2.7%CVE-2023-38952HIGHInsecure access control in ZKTeco BioTime through 9.0.1 allows authenticated attackers to escalate their privileges due to the fact that sesEPSS 2.7%CVE-2022-33901MEDIUMWordPress MultiSafepay plugin for WooCommerce plugin <= 4.13.1 - Unauthenticated Arbitrary File Read vulnerabilityEPSS 2.7%CVE-2024-4836HIGHLFI in sites managed by Edito CMSEPSS 2.7%CVE-2021-43821CRITICALFiles Accessible to External Parties in OpencastEPSS 2.0%CVE-2025-34110CRITICALColoradoFTP Server <= 1.3 Build 8 Path Traversal Information DisclosureEPSS 1.9%CVE-2024-27894HIGHApache Pulsar: Pulsar Functions Worker Allows Unauthorized File Access and Unauthorized HTTP/HTTPS ProxyingEPSS 1.9%CVE-2022-39208HIGHGit Repository Disclosure in OnedevEPSS 1.8%CVE-2020-1726MEDIUMA flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they areEPSS 1.8%CVE-2017-12079—Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2EPSS 1.8%CVE-2019-10930—A vulnerability has been identified in All other SIPROTEC 5 device types with CPU variants CP300 and CP100 and the respective Ethernet commuEPSS 1.8%CVE-2021-21355HIGHUnrestricted File Upload in Form FrameworkEPSS 1.6%CVE-2021-1361CRITICALCisco NX-OS Software Unauthenticated Arbitrary File Actions VulnerabilityEPSS 1.6%CVE-2019-13941—A vulnerability has been identified in OZW672 (All versions < V10.00), OZW772 (All versions < V10.00). Vulnerable versions of OZW Web ServerEPSS 1.6%CVE-2023-39479MEDIUMSofting Secure Integration Server OPC UA Gateway Directory Creation VulnerabilityEPSS 1.6%CVE-2025-68109CRITICALChurchCRM vulnerable to RCE with database restore functionalityEPSS 1.5%CVE-2019-3569—HHVM, when used with FastCGI, would bind by default to all available interfaces. This behavior could allow a malicious individual unintendedEPSS 1.5%CVE-2026-25231HIGHFileRise affected by an Unauthenticated File Read Due to Insufficient Access ControlEPSS 1.5%CVE-2021-4463HIGHLongjing Technology BEMS API <= 1.21 Remote Arbitrary File DownloadEPSS 1.5%