Falhas do tipo CWE-22

6.017 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2025-69620MEDIUMA path traversal in Moo Chan Song v4.5.7 allows attackers to cause a Denial of Service (DoS) via writing files to the internal storage.EPSS 0.3%CVE-2023-42947HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.7.2, macOS Ventura 13.6.3, iOS 17.2 aEPSS 0.3%CVE-2026-12568MEDIUMArbitrary File Write in postman_download moduleEPSS 0.3%CVE-2026-59839MEDIUMA improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortEPSS 0.3%CVE-2023-24592HIGHPath traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentiallyEPSS 0.3%CVE-2025-43314MEDIUMA parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7, mEPSS 0.3%CVE-2026-54561MEDIUMMCP Memory Keeper: Arbitrary local file read in mcp-memory-keeper context_import via unvalidated filePathEPSS 0.2%CVE-2026-15791LOWLLB file operation can be tricked to remove /tmp directory contentsEPSS 0.2%CVE-2025-43196HIGHA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2024-27827MEDIUMThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.5, macOS Ventura 13.6.7. An app may be abEPSS 0.2%CVE-2024-44190MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7EPSS 0.2%CVE-2022-3560MEDIUMA flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script tEPSS 0.2%CVE-2025-43191MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2026-3479NONEpkgutil.get_data() does not enforce documented restrictionsEPSS 0.2%CVE-2026-8770MEDIUMcontinuedev continue JSON-RPC Server lsTool.ts lsTool path traversalEPSS 0.2%CVE-2025-3424HIGH3.2.1 Arbitrary File Read in insecure .NET Remoting TCP ChannelEPSS 0.2%CVE-2022-4123LOWA flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resultingEPSS 0.2%CVE-2024-0129MEDIUMNVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extractioEPSS 0.2%CVE-2026-54319MEDIUMDaytona: Path traversal in sandbox volume id mounts arbitrary host paths into the sandbox — cross-tenant data access and host escapeEPSS 0.2%CVE-2022-29093HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%