Falhas do tipo CWE-281

225 resultados

Preservação inadequada de permissões

Quando um programa cria, copia ou modifica arquivos e recursos, mas não mantém ou herda as permissões originais corretamente, permitindo acesso indevido. Isso expõe dados sensíveis ou permite que usuários não autorizados executem operações críticas.

Exemplo

Um backup que copia arquivos de configuração com credenciais, mas muda as permissões para leitura por qualquer usuário do sistema. Ou um instalador que cria diretórios temporários com permissões padrão abertas, deixando senhas de sessão visíveis para outros usuários locais.

Como mitigar

Sempre defina explicitamente permissões restritivas (ex: 0600 para arquivos sensíveis) logo após criar ou copiar arquivos. Use funções seguras da plataforma (chmod, SetSecurityDescriptor) e valide que as permissões foram aplicadas corretamente antes de escrever dados sensíveis.

CVE-2024-54557HIGHA logic issue was addressed with improved restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2EPSS 0.5%CVE-2022-31096MEDIUMInvites restricted to an email or invite links restricted to an email domain may be bypassed by a under certain conditions in DiscourseEPSS 0.5%CVE-2024-22404MEDIUMPermissions bypass in Nextcloud with the files zip appEPSS 0.5%CVE-2024-54818HIGHSourceCodester Computer Laboratory Management System 1.0 is vulnerable to Incorrect Access Control. via /php-lms/admin/?page=user/list.EPSS 0.5%CVE-2024-22402MEDIUMImproper handling of request URLs in Nextcloud Guests app allows guest users to bypass app allowlistEPSS 0.5%CVE-2024-27795HIGHA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15. A camera extension may be able to aEPSS 0.5%CVE-2024-30187MEDIUMAnope before 2.0.15 does not prevent resetting the password of a suspended account.EPSS 0.5%CVE-2025-43698CRITICALImproper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows bypass of field level security controls for SEPSS 0.5%CVE-2024-41648HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2024-32882LOWPermission check bypass when editing a model with per-field restrictions in wagtailEPSS 0.5%CVE-2024-41650HIGHInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.5%CVE-2021-3418If certificates that signed grub are installed into db, grub can be booted directly. It will then boot any kernel without signature validatiEPSS 0.5%CVE-2021-3847An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the wEPSS 0.5%CVE-2024-50920HIGHInsecure permissions in Silicon Labs (SiLabs) Z-Wave Series 700 and 800 v7.21.1 allow attackers to create a fake node via supplying crafted EPSS 0.5%CVE-2024-22401MEDIUMAll users can reset the allowed apps list for Nextcloud Guest App usersEPSS 0.5%CVE-2021-21379HIGHIt's possible to execute anything with the rights of the author of a macro which uses the {{wikimacrocontent}} macroEPSS 0.5%CVE-2024-36532CRITICALInsecure permissions in kruise v1.6.2 allows attackers to access sensitive data and escalate privileges by obtaining the service account's tEPSS 0.5%CVE-2024-33892MEDIUMInsecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible toEPSS 0.4%CVE-2025-25871HIGHAn issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions functionEPSS 0.4%CVE-2023-42228HIGHPat Infinite Solutions HelpdeskAdvanced <= 11.0.33 is vulnerable to Incorrect Access Control. Low privileged users can edit their own ACL ruEPSS 0.4%