Fallos del tipo CWE-732

791 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2025-1731HIGHAn incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 EPSS 0.9%CVE-2021-32526MEDIUMQSAN Storage Manager - Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2019-3683HIGHkeystone_json_assignment backend granted access to any project for users in user-project-map.jsonEPSS 0.9%CVE-2021-40331HIGHPermissions problem in the Apache Ranger Hive PluginEPSS 0.9%CVE-2021-38475HIGHAUVESY VersiondogEPSS 0.9%CVE-2021-22648HIGHOvarro TBox Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2021-35248MEDIUMUnrestricted access to Orion.UserSettings SWIS entity for low-privilege usersEPSS 0.9%CVE-2023-28346HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API EPSS 0.9%CVE-2022-48257MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.EPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2017-8450X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a doEPSS 0.9%CVE-2025-21584MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.9%CVE-2025-21581MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-21585MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-30685MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-30684MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-30683MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2022-35250MEDIUMA privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to viEPSS 0.9%CVE-2025-21583MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0EPSS 0.8%