Fallos del tipo CWE-696

40 resultados

Ordem incorreta de operações de segurança

A aplicação executa operações críticas de segurança em sequência errada, permitindo que um estado intermediário seja explorado antes de validações ou proteções serem aplicadas. Por exemplo: conceder acesso antes de completar autenticação, ou usar dados antes de sanitizá-los.

Ejemplo

Um sistema que carrega dados do usuário em memória, aplica lógica de negócio, e só depois valida permissões. Um atacante pode manipular o fluxo para processar operações sensíveis antes da validação de autorização ocorrer, contornando controles de acesso.

Cómo mitigar

Sempre execute validações (autenticação, autorização, sanitização) antes de qualquer operação sensível. Arquitete o fluxo com camadas de defesa ordenadas: verificar credenciais → validar permissões → sanitizar entrada → processar dados. Use testes de segurança para confirmar a sequência.

CVE-2023-33224HIGHSolarWinds Platform Incorrect Behavior Order VulnerabilityEPSS 2.8%CVE-2021-22569HIGHDenial of Service of protobuf-java parsing procedureEPSS 1.7%CVE-2021-31379HIGHJunos OS: MX Series: MPC 7/8/9/10/11 cards with MAP-E: PFE halts when an attacker sends malformed IPv4 or IPv6 traffic inside the MAP-E tunnel.EPSS 1.3%CVE-2023-44386MEDIUMIncorrect request error handling triggers server crash in VaporEPSS 0.6%CVE-2025-31485HIGHGraphQL grant on a property might be cached with different objectsEPSS 0.6%CVE-2025-0150HIGHZoom Workplace Apps for iOS - Incorrect Behavior OrderEPSS 0.5%CVE-2026-44919MEDIUMIn OpenStack Ironic through 35.x before a3f6d73, during image handling, an infinite loop in checksum calculations can occur via the file:///EPSS 0.5%CVE-2026-44108CRITICALFirewall bypass during shutdownEPSS 0.5%CVE-2025-48965MEDIUMMbed TLS before 3.6.4 has a NULL pointer dereference because mbedtls_asn1_store_named_data can trigger conflicting data with val.p of NULL bEPSS 0.5%CVE-2026-35627MEDIUMOpenClaw < 2026.3.22 - Unauthenticated Cryptographic Work in Nostr Inbound DM HandlingEPSS 0.5%CVE-2026-65100MEDIUMApache Traffic Server: HPACK encoder desynchronizes from the decoder after a failed header encodeEPSS 0.4%CVE-2026-35640MEDIUMOpenClaw < 2026.3.25 - Denial of Service via Unauthenticated Webhook Request ParsingEPSS 0.4%CVE-2026-35652MEDIUMOpenClaw < 2026.3.22 - Unauthorized Action Execution via Callback DispatchEPSS 0.4%CVE-2023-52968MEDIUMMariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.EPSS 0.4%CVE-2026-56355LOWGNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.EPSS 0.4%CVE-2024-35229MEDIUMZKsync Era evaluation order of Yul function argumentsEPSS 0.4%CVE-2026-44600LOWTor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.EPSS 0.4%CVE-2026-40583HIGHUltraDAG: SmartOp Vote Path Triggers Fatal Supply Invariant HaltEPSS 0.4%CVE-2026-43002MEDIUMAn issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before aEPSS 0.4%CVE-2026-41254MEDIUMLittle CMS (lcms2) through 2.18 has an integer overflow in CubeSize in cmslut.c because the overflow check is performed after the multiplicaEPSS 0.4%