Falhas do tipo CWE-281

225 resultados

Preservação inadequada de permissões

Quando um programa cria, copia ou modifica arquivos e recursos, mas não mantém ou herda as permissões originais corretamente, permitindo acesso indevido. Isso expõe dados sensíveis ou permite que usuários não autorizados executem operações críticas.

Exemplo

Um backup que copia arquivos de configuração com credenciais, mas muda as permissões para leitura por qualquer usuário do sistema. Ou um instalador que cria diretórios temporários com permissões padrão abertas, deixando senhas de sessão visíveis para outros usuários locais.

Como mitigar

Sempre defina explicitamente permissões restritivas (ex: 0600 para arquivos sensíveis) logo após criar ou copiar arquivos. Use funções seguras da plataforma (chmod, SetSecurityDescriptor) e valide que as permissões foram aplicadas corretamente antes de escrever dados sensíveis.

CVE-2024-54880CRITICALSeaCMS V13.1 is vulnerable to Incorrect Access Control. A logic flaw can be exploited by an attacker to allow any user to register accounts EPSS 0.9%CVE-2024-54465CRITICALA logic issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2. An app may be able to elevate privileEPSS 0.9%CVE-2024-56973CRITICALInsecure Permissions vulnerability in Alvaria, Inc Unified IP Unified Director before v.7.2SP2 allows a remote attacker to execute arbitraryEPSS 0.9%CVE-2021-3523A flaw was found in 3Scale APICast in versions prior to 2.11.0, where it incorrectly identified connections for reuse. This flaw allows an aEPSS 0.8%CVE-2023-28668CRITICALJenkins Role-based Authorization Strategy Plugin 587.v2872c41fa_e51 and earlier grants permissions even after they've been disabled.EPSS 0.8%CVE-2022-36102MEDIUMAcess control list bypassed via crafted specific URLsEPSS 0.8%CVE-2022-36062HIGHGrafana folders admin only permission privilege escalationEPSS 0.7%CVE-2023-34672Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting uEPSS 0.7%CVE-2024-1726MEDIUMQuarkus: security checks for some inherited endpoints performed after serialization in resteasy reactive may trigger a denial of serviceEPSS 0.7%CVE-2023-48240CRITICALXWiki Platform sends cookies to external images in rendered diff and is vulnerable to server side request forgeryEPSS 0.7%CVE-2024-41644CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41646CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41645CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2024-41649CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2022-38473HIGHA cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). ThisEPSS 0.7%CVE-2019-14841HIGHA flaw was found in the RHDM, where an authenticated attacker can change their assigned role in the response header. This flaw allows an attEPSS 0.7%CVE-2023-41939HIGHJenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users fEPSS 0.7%CVE-2021-3414A flaw was found in satellite. When giving granular permission related to the organization, other permissions allowing a user to view and maEPSS 0.7%CVE-2025-34298HIGHNagios Log Server < 2024R1.3.2 Set Email Privilege EscalationEPSS 0.7%CVE-2023-32552An Improper access control vulnerability in Trend Micro Apex One and Apex One as a Service could allow an unauthenticated user under certainEPSS 0.6%