Fallos del tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

É quando um controle de segurança implementado no código falha ou é contornado, permitindo que ameaças que deveriam ser bloqueadas passem. Pode ser autenticação fraca, validação inadequada ou criptografia mal aplicada — o mecanismo existe, mas não funciona conforme deveria.

Ejemplo

Um sistema implementa autenticação por token JWT, mas não valida corretamente a assinatura ou a expiração do token. Um atacante reutiliza um token expirado ou falsificado e acessa a API como usuário autêntico, porque o mecanismo de proteção falhou em sua verificação.

Cómo mitigar

Revise e teste rigorosamente cada mecanismo de segurança (autenticação, autorização, validação de entrada, criptografia). Use bibliotecas maduras e bem auditadas, implemente testes automatizados que verifiquem falhas intencional de proteção, e considere code reviews com foco em segurança.

CVE-2021-31386MEDIUMJunos OS: When using J-Web with HTTP an attacker may retrieve encryption keys via Person-in-the-Middle attacks.EPSS 0.7%CVE-2026-26332CRITICALvm2: Sandbox EscapeEPSS 0.7%CVE-2022-43422MEDIUMJenkins Compuware Topaz Utilities Plugin 1.0.8 and earlier implements an agent/controller message that does not limit where it can be executEPSS 0.7%CVE-2024-38070HIGHWindows LockDown Policy (WLDP) Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2022-47544CRITICALAn issue was discovered in Siren Investigate before 12.1.7. Script variable whitelisting is insufficiently sandboxed.EPSS 0.7%CVE-2022-43424MEDIUMJenkins Compuware Xpediter Code Coverage Plugin 1.0.7 and earlier implements an agent/controller message that does not limit where it can beEPSS 0.7%CVE-2026-18428HIGHSQL Query Validation Bypass in OpenSearch Direct QueryEPSS 0.7%CVE-2023-0085MEDIUMMetform Elementor Contact Form Builder <= 3.2.1 - reCaptcha Protection BypassEPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2024-38203MEDIUMWindows Package Library Manager Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43434MEDIUMJenkins NeuVector Vulnerability Scanner Plugin 1.20 and earlier programmatically disables Content-Security-Policy protection for user-generaEPSS 0.7%CVE-2025-21384HIGHAzure Health Bot Elevation of Privilege VulnerabilityEPSS 0.7%CVE-2026-25056CRITICALn8n Arbitrary File Write leading to RCE in n8n Merge NodeEPSS 0.7%CVE-2025-21346HIGHMicrosoft Office Security Feature Bypass VulnerabilityEPSS 0.7%CVE-2026-22686CRITICALSandbox Escape via Host Error Prototype Chain in enclave-vmEPSS 0.7%CVE-2019-13516—In OSIsoft PI Web API and prior, the affected product is vulnerable to a direct attack due to a cross-site request forgery protection settinEPSS 0.7%CVE-2022-43435MEDIUMJenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in worEPSS 0.7%CVE-2025-27665CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Antivirus Protection aEPSS 0.7%CVE-2023-30851LOWPotential HTTP policy bypass when using header rules in CiliumEPSS 0.7%CVE-2024-5691MEDIUMBy tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would EPSS 0.7%