Fallos del tipo CWE-669

76 resultados

Transferência incorreta de recurso entre contextos de segurança

Ocorre quando um recurso (arquivo, conexão, memória, token) é movido ou compartilhado entre contextos de segurança diferentes sem validação ou isolamento adequado. Um código pode transferir um recurso de um contexto protegido para um contexto menos confiável, expondo-o a acesso não autorizado ou manipulação.

Ejemplo

Uma aplicação web recebe um arquivo de um usuário autenticado, valida-o como seguro, mas depois o armazena em um diretório acessível ao servidor web que roda com menos privilégios. Um outro processo ou usuário consegue acessar ou modificar esse arquivo porque o contexto de segurança original foi perdido durante a transferência.

Cómo mitigar

Mantenha a validação e as restrições de segurança do recurso durante toda sua transferência entre contextos. Use mecanismos como ACLs apropriadas, validação em cada fronteira de segurança, isolamento de processos, e evite confiar em estado de segurança anterior — revalide a cada transição.

CVE-2025-56675LOWThe EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive informaEPSS 0.2%CVE-2026-32772LOWtelnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.EPSS 0.2%CVE-2023-32803HIGHThe ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certEPSS 0.2%CVE-2026-48831HIGHWine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some coEPSS 0.2%CVE-2026-86144MEDIUMIn xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevanceEPSS 0.2%CVE-2026-40228LOWIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is execEPSS 0.2%CVE-2026-41030MEDIUMIn ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.EPSS 0.2%CVE-2026-73281LOWIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that aEPSS 0.2%CVE-2025-59453LOWClick Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a craftEPSS 0.2%CVE-2025-45480LOWFloodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.EPSS 0.2%CVE-2026-40225MEDIUMIn udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.EPSS 0.1%CVE-2025-59378MEDIUMIn guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular EPSS 0.1%CVE-2025-54956LOWThe gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the correspondinEPSS 0.1%CVE-2026-41525MEDIUMKDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandboEPSS 0.1%CVE-2026-38924LOWIn Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 wasEPSS 0.1%CVE-2026-89162LOWIn PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available EPSS 0.1%