Fallos del tipo CWE-732

791 resultados

Permissões inadequadas em recurso crítico de segurança

A aplicação ou sistema define permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários não autorizados leiam ou modifiquem dados sensíveis. Isso expõe segredos (chaves API, senhas, tokens), permite alteração de configurações críticas ou compromete a integridade do sistema.

Ejemplo

Um arquivo de configuração contendo credenciais de banco de dados é criado com permissões 644 (leitura global) em vez de 600, permitindo que qualquer usuário do sistema leia as credenciais. Ou um diretório com chaves privadas SSH é criado com permissões 777, deixando-o acessível e modificável por todos.

Cómo mitigar

Defina permissões restritivas no momento da criação (umask 0077 para arquivos sensíveis, chmod 600 para segredos). Revise e audite permissões de recursos críticos regularmente, especialmente após deploy. Use controle de acesso baseado em papéis (RBAC) e aplique o princípio do menor privilégio.

CVE-2025-21580MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.7%CVE-2025-21579MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.EPSS 0.7%CVE-2023-0225MEDIUMA flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this atEPSS 0.7%CVE-2022-40756HIGHIf folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01EPSS 0.7%CVE-2023-35168MEDIUMDataEase has a privilege bypass vulnerabilityEPSS 0.7%CVE-2022-4365MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 beforeEPSS 0.7%CVE-2024-37087MEDIUMThe vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-oEPSS 0.7%CVE-2022-43946HIGHMultiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check timeEPSS 0.7%CVE-2024-41647CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2025-21566MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 anEPSS 0.7%CVE-2022-40298HIGHCrestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found EPSS 0.7%CVE-2022-46338MEDIUMg810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable anEPSS 0.7%CVE-2023-22294HIGHPrivilege escalation in Checkmk ApplianceEPSS 0.7%CVE-2022-36103HIGHTalos worker join token can be used to get elevated access level to the Talos APIEPSS 0.7%CVE-2024-44729HIGHIncorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenEPSS 0.7%CVE-2024-12564MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in ODA CDE inWEB SDK before 2025.3EPSS 0.7%CVE-2025-30708HIGHVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions tEPSS 0.7%CVE-2025-34212HIGHVasion Print (formerly PrinterLogic) Insecure Build PipelineEPSS 0.7%CVE-2024-24117CRITICALInsecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via tEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%