Falhas do tipo CWE-22

6.020 resultados

Travessia de diretório (Path Traversal)

A aplicação constrói caminhos de arquivo usando entrada do usuário sem validar adequadamente, permitindo que caracteres especiais como '../' façam o caminho "sair" do diretório permitido e acessar arquivos fora da zona restrita. Isso expõe dados sensíveis ou permite manipulação de arquivos críticos do sistema.

Exemplo

Um site permite download de documentos via URL como /download?file=relatorio.pdf, mas não valida o parâmetro. Um atacante usa /download?file=../../etc/passwd para ler o arquivo de senhas do servidor, ou /download?file=../../configuracao.db para acessar a base de dados da aplicação.

Como mitigar

Valide e normalize todos os caminhos de entrada (use funções nativas como realpath ou canonicalize), implemente uma whitelist de arquivos permitidos em vez de bloquear padrões perigosos, e configure permissões de arquivo restritivas no SO. Melhor ainda: nunca construa caminhos a partir de entrada do usuário — use índices ou IDs mapeados internamente.

CVE-2022-29093HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2022-29094HIGHDell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versionEPSS 0.2%CVE-2026-101885HIGHZeroClaw before 0.8.5 Path Traversal via Plugin Manifest wasm_pathEPSS 0.2%CVE-2026-78394MEDIUMLink Library < 7.9.6 - Contributor+ Path Traversal via 'filepath' ParameterEPSS 0.2%CVE-2024-31965MEDIUMA vulnerability on Mitel 6800 Series and 6900 Series SIP Phones through 6.3 SP3 HF4, 6900w Series SIP Phone through 6.3.3, and 6970 ConferenEPSS 0.2%CVE-2026-55557HIGHbrowse-mcp: Arbitrary file write via unconfined download and state pathsEPSS 0.2%CVE-2024-31552HIGHCuteHttpFileServer v.3.1 version has an arbitrary file download vulnerability, which allows attackers to download arbitrary files on the serEPSS 0.2%CVE-2024-36508MEDIUMAn improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.EPSS 0.2%CVE-2023-40439LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 16.6 and iPadOS 16.6, macOS VEPSS 0.2%CVE-2026-18114MEDIUMIBM Financial Transaction Manager (FTM) is Impacted by Multiple VulnerabilitiesEPSS 0.2%CVE-2023-25508MEDIUMNVIDIA DGX-1 BMC contains a vulnerability in the IPMI handler, where an attacker with the appropriate level of authorization can upload and EPSS 0.2%CVE-2025-0750MEDIUMCri-o: cri-o path traversal in log handling functions allows arbitrary unmountingEPSS 0.2%CVE-2023-6407MEDIUM A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause arbitrary fiEPSS 0.2%CVE-2026-73234HIGHFreeCAD: FCStd path traversal allows arbitrary file write via unsanitized file attribute in PropertyFileIncluded::Restore()EPSS 0.2%CVE-2026-41972MEDIUMPath traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2025-43250MEDIUMA path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura EPSS 0.2%CVE-2026-24686MEDIUMgo-tuf Path Traversal in TAP 4 Multirepo Client Allows Arbitrary File Write via Malicious Repository NamesEPSS 0.2%CVE-2026-51888HIGHlangflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storaEPSS 0.2%CVE-2026-47487MEDIUMNVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, wrEPSS 0.2%CVE-2024-0849MEDIUMLeanote 2.7.0 - Local File ReadEPSS 0.2%