Falhas do tipo CWE-282

29 resultados

Gestão inadequada de propriedade de recursos

Ocorre quando um aplicativo não estabelece ou valida corretamente quem é o dono de um recurso (arquivo, processo, objeto em memória, etc), permitindo que usuários acessem ou modifiquem dados que não lhes pertencem. O risco é perda de controle de acesso: um atacante assume controle de um recurso crítico porque o sistema não verificou propriedade antes da operação.

Exemplo

Um aplicativo web cria arquivos temporários sem definir permissões restritivas ou sem validar que o usuário logado é quem criou o arquivo. Um atacante consegue ler ou sobrescrever arquivos de outros usuários porque o sistema não enforça a propriedade. Outro cenário: um processo root executa código que modifica um arquivo cuja propriedade não foi verificada, permitindo privilege escalation.

Como mitigar

Sempre estabeleça propriedade explícita quando criar recursos (quem criou é o proprietário); valide a propriedade antes de qualquer operação de leitura, escrita ou exclusão; use permissões de arquivo restrictivas (ex: 0600 para privado) e mecanismos de autorização da plataforma (ACLs, SELinux) para enforçar propriedade.

CVE-2023-0386HIGHA flaw was found in the Linux kernel, where unauthorized access to the execution of the setuid file with capabilities was found in the LinuxEPSS 7.9%KEVCVE-2026-23514HIGHKiteworks Core before 9.2.2 is vulnerable to Improper Ownership ManagementEPSS 1.0%CVE-2024-8949MEDIUMSourceCodester Online Eyewear Shop Cart Content Master.php improper ownership managementEPSS 0.7%CVE-2024-3383HIGHPAN-OS: Improper Group Membership Change Vulnerability in Cloud Identity Engine (CIE)EPSS 0.6%CVE-2020-10632HIGHICSA-20-140-02 Emerson OpenEnterpriseEPSS 0.5%CVE-2022-29187HIGHBypass of safe.directory protections in GitEPSS 0.4%CVE-2023-7226MEDIUMmeetyoucrop big-whale Admin Module all.api improper ownership managementEPSS 0.4%CVE-2023-0989MEDIUMImproper Ownership Management in GitLabEPSS 0.4%CVE-2024-39755HIGHA privilege escalation vulnerability exists in the node update functionality of Veertu Anka Build 1.42.0. A specially crafted PKG file can lEPSS 0.4%CVE-2025-32946MEDIUMPeerTube Arbitrary Playlist Creation via ActivityPub ProtocolEPSS 0.4%CVE-2024-45103MEDIUMA valid, authenticated LXCA user may be able to unmanage an LXCA managed device in through the LXCA web interface without sufficient privileEPSS 0.3%CVE-2017-12189It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handlinEPSS 0.3%CVE-2024-47816MEDIUMUsers can impersonate import requesters if their actor IDs coincide in ImportDumpEPSS 0.3%CVE-2025-32945MEDIUMPeerTube Arbitrary Playlist Creation via REST APIEPSS 0.3%CVE-2024-43176MEDIUMIBM OpenPages information disclosureEPSS 0.3%CVE-2024-13246MEDIUMNode Access Rebuild Progressive - Less critical - Access bypass - SA-CONTRIB-2024-010EPSS 0.3%CVE-2026-50130HIGHPi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`EPSS 0.3%CVE-2026-3867MEDIUMAn improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because of improper ownership management, a low-EPSS 0.2%CVE-2025-67642MEDIUMJenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set the appropriate context for Vault credentials lookup, allowing aEPSS 0.2%CVE-2022-0026MEDIUMCortex XDR Agent: Unintended Program Execution Leads to Local Privilege Escalation (PE) VulnerabilityEPSS 0.2%