Fallos del tipo CWE-732

792 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2025-1139MEDIUMIBM Edge Application Manager incorrect permissionsEPSS 0.1%CVE-2024-32014MEDIUMA vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alteEPSS 0.1%CVE-2026-77268MEDIUMMCP Atlassian: Insecure File Permissions on OAuth Token StorageEPSS 0.1%CVE-2026-6842LOWNano: nano: local attacker can inject malicious .desktop launcher due to insecure directory permissionsEPSS 0.1%CVE-2026-29125HIGHIDC SFX2100 Satellite Receiver allows unprivileged modification of DNS configuration due to world-writable `/etc/resolv.conf`EPSS 0.1%CVE-2026-0271MEDIUMPrisma Access Agent: Local Privilege Escalation by Authorized UsersEPSS 0.1%CVE-2021-4480HIGHDräger Protector Software Local Privilege Escalation via Insecure File PermissionsEPSS 0.1%CVE-2021-4481HIGHDräger Protector Software Local Privilege Escalation via Insecure File PermissionsEPSS 0.1%CVE-2023-20923MEDIUMIn exported content providers of ShannonRcs, there is a possible way to get access to protected content providers due to a permissions bypasEPSS 0.1%CVE-2026-22676HIGHBarracuda RMM < 2025.2.2 Privilege Escalation via Insecure Directory PermissionsEPSS 0.1%CVE-2026-15779MEDIUMSamba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validationEPSS 0.1%CVE-2025-33088HIGHMultiple Vulnerabilities in IBM Concert Software.EPSS 0.1%CVE-2025-40818LOWA vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLSEPSS 0.1%CVE-2024-58383HIGHFroxlor before 2.2.0 Insecure File Permissions mysql.confEPSS 0.1%CVE-2026-91798HIGHFoxit PDF Editor/Reader Updater Privilege EscalationEPSS 0.1%CVE-2024-0019MEDIUMIn setListening of AppOpsControllerImpl.java, there is a possible way to hide the microphone privacy indicator when restarting systemUI due EPSS 0.1%CVE-2026-21765HIGHHCL BigFix Platform is affected by insecure permissions on private cryptographic keysEPSS 0.1%CVE-2026-82312LOWOpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial of service via a NULEPSS 0.1%CVE-2025-64996MEDIUMOverly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's outputEPSS 0.1%CVE-2026-4482MEDIUMInsight Agent Private Key Information Disclosure via Inherited File PermissionsEPSS 0.1%