Fallos del tipo CWE-732

790 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2024-2905MEDIUMRpm-ostree: world-readable /etc/shadow fileEPSS 0.3%CVE-2019-19335MEDIUMDuring installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and EPSS 0.3%CVE-2022-32929MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.EPSS 0.3%CVE-2025-34323HIGHNagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo RulesEPSS 0.3%CVE-2023-49797HIGHLocal Privilege Escalation in pyinstaller on WindowsEPSS 0.3%CVE-2023-31142LOWDiscourse's general category permissions could be set back to defaultEPSS 0.3%CVE-2023-49257HIGHCommand execution using the certificate upload utilityEPSS 0.3%CVE-2025-12004CRITICALThe compare API module breaks Extension:LockdownEPSS 0.3%CVE-2024-45164MEDIUMAkamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch anEPSS 0.3%CVE-2024-39967MEDIUMInsecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.EPSS 0.3%CVE-2019-19341MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files inclEPSS 0.3%CVE-2025-52873HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2025-54497HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2020-10781MEDIUMA flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read theEPSS 0.3%CVE-2019-5642LOWMAGICKEPSS 0.3%CVE-2025-0093HIGHIn handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lEPSS 0.3%CVE-2024-41954MEDIUMFOG Weak file permissionsEPSS 0.3%CVE-2016-8637MEDIUMA local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'eEPSS 0.3%CVE-2024-6360MEDIUMIncorrect Permission Assignment for Critical Resource vulnerability has been discovered in OpenText™ Vertica.EPSS 0.3%CVE-2023-3322HIGH Code Execution through overwriting service executable in utilities directoryEPSS 0.3%