Fallos del tipo CWE-669

76 resultados

Transferência incorreta de recurso entre contextos de segurança

Ocorre quando um recurso (arquivo, conexão, memória, token) é movido ou compartilhado entre contextos de segurança diferentes sem validação ou isolamento adequado. Um código pode transferir um recurso de um contexto protegido para um contexto menos confiável, expondo-o a acesso não autorizado ou manipulação.

Ejemplo

Uma aplicação web recebe um arquivo de um usuário autenticado, valida-o como seguro, mas depois o armazena em um diretório acessível ao servidor web que roda com menos privilégios. Um outro processo ou usuário consegue acessar ou modificar esse arquivo porque o contexto de segurança original foi perdido durante a transferência.

Cómo mitigar

Mantenha a validação e as restrições de segurança do recurso durante toda sua transferência entre contextos. Use mecanismos como ACLs apropriadas, validação em cada fronteira de segurança, isolamento de processos, e evite confiar em estado de segurança anterior — revalide a cada transição.

CVE-2026-44599LOWTor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.EPSS 0.3%CVE-2026-40552MEDIUMRemote Code Execution in mpGabinetEPSS 0.3%CVE-2026-75010MEDIUMIn Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa driver of the password plugin could leak a Modoboa API authenticationEPSS 0.3%CVE-2026-44917MEDIUMOpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Ironic conductor via a pEPSS 0.3%CVE-2025-62775HIGHMercku M6a devices through 2.1.0 allow root TELNET logins via the web admin password.EPSS 0.3%CVE-2026-46448MEDIUMIn OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.EPSS 0.3%CVE-2026-12068HIGHAvira Password Manager credential disclosure via cross-origin autofill in FirefoxEPSS 0.3%CVE-2026-46447MEDIUMOpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_infoEPSS 0.3%CVE-2026-87724MEDIUMTor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_REQUEST was not sent, which allows remote attackers to cause a denial EPSS 0.3%CVE-2025-46553LOW@misskey-dev/summaly Redirect Filter BypassEPSS 0.2%CVE-2024-31573MEDIUMXMLUnit for Java before 2.10.0, in the default configuration, might allow code execution via an untrusted stylesheet (used for an XSLT transEPSS 0.2%CVE-2026-33265MEDIUMIn LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.EPSS 0.2%CVE-2025-62292MEDIUMIn SonarQube before 25.6, 2025.3 Commercial, and 2025.1.3 LTA, authenticated low-privileged users can query the /api/v2/users-management/useEPSS 0.2%CVE-2026-25832LOWIn Mbed TLS 3.6.x before 3.6.7 and 4.1.x before 4.1.2, the TLS 1.3 client accepts HelloRetryRequest selecting an unadvertised group.EPSS 0.2%CVE-2025-59691LOWPureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as WiEPSS 0.2%CVE-2025-59692LOWPureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and applyEPSS 0.2%CVE-2025-26698LOWIncorrect resource transfer between spheres issue exists in RevoWorks SCVX and RevoWorks Browser. If exploited, malicious files may be downlEPSS 0.2%CVE-2023-37253LOWAn issue was discovered in the ProofreadPage extension for MediaWiki through 1.39.3. It leaks information about a suppressed user via the APEPSS 0.2%CVE-2023-37252LOWAn issue was discovered in the CheckUser extension for MediaWiki through 1.39.3. Special:CheckUserLog shows usernames that have been hidden.EPSS 0.2%CVE-2026-73574LOWIn Zimbra Collaboration before 10.1.17, a local file inclusion (LFI) vulnerability exists in the Zimbra Classic Web Client due to improper vEPSS 0.2%