Falhas do tipo CWE-22

5.927 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2022-4594MEDIUMdrogatkin TJWS2 WarRoller.java deployWar path traversalEPSS 0.6%CVE-2025-5741MEDIUMCWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary file EPSS 0.6%CVE-2026-82393HIGHpnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installEPSS 0.6%CVE-2022-46902MEDIUMAn issue was discovered in Vocera Report Server and Voice Server 5.x through 5.8. There is a Path Traversal for an Unzip operation. The VoceEPSS 0.6%CVE-2024-44167HIGHThis issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, EPSS 0.6%CVE-2024-52444HIGHWordPress Opal Woo Custom Product Variation plugin <= 1.1.3 - Arbitrary File Deletion vulnerabilityEPSS 0.6%CVE-2023-49058LOWDirectory Traversal vulnerability in SAP Master Data GovernanceEPSS 0.6%CVE-2023-42456LOWsudo-rs Session File Relative Path Traversal vulnerabilityEPSS 0.6%CVE-2023-37476MEDIUMZip slip in OpenRefineEPSS 0.6%CVE-2026-50757HIGHDirectory Traversal vulnerability in DayuanJiang next-ai-draw-io 0.4.13 allowsa remote attacker to execute arbitrary code via the nex-ai-draEPSS 0.6%CVE-2025-23250HIGHNVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory EPSS 0.6%CVE-2026-56233HIGHCapgo - SSRF and Privilege Escalation via Path Traversal in Builder Upload ProxyEPSS 0.6%CVE-2026-4222MEDIUMSSCMS download PathUtils.RemoveParentPath path traversalEPSS 0.6%CVE-2023-49089HIGHUmbraco CMS possible path traversal when creating packages from backofficeEPSS 0.6%CVE-2026-33670CRITICALSiYuan has directory traversal within its publishing serviceEPSS 0.6%CVE-2025-23422HIGHWordPress Store Locator plugin <= 3.98.10 - Local File Inclusion vulnerabilityEPSS 0.6%CVE-2026-4044MEDIUMprojectsend Delete import-orphans.php realpath path traversalEPSS 0.6%CVE-2025-6070MEDIUMRestrict File Access <= 1.1.2 - Authenticated (Subscriber+) Arbitrary File ReadEPSS 0.6%CVE-2025-58072HIGHImproper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:EPSS 0.6%CVE-2025-56815HIGHDatart 1.0.0-rc.3 is vulnerable to Directory Traversal in the POST /viz/image interface, since the server directly uses MultipartFile.transfEPSS 0.6%