Falhas do tipo CWE-284

7.074 resultados

Controle de acesso inadequado a recursos

A aplicação falha em validar ou aplica incorretamente as restrições de acesso, permitindo que usuários não autorizados acessem dados ou funcionalidades que deveriam estar protegidas. É uma das fragilidades mais comuns em segurança: o código não verifica corretamente quem está pedindo acesso e simplesmente concede.

Exemplo

Um e-commerce que permite acessar o perfil de qualquer cliente substituindo o ID na URL (ex: /usuario/123 → /usuario/124), sem validar se o usuário autenticado é o dono daquele perfil. Um atacante consegue ver dados pessoais, histórico de compras e endereços de outras pessoas.

Como mitigar

Implemente verificações explícitas em cada acesso a recurso: autentique o usuário, identifique qual recurso ele quer acessar, e valide se as permissões dele cobrem aquele recurso específico. Use listas de controle de acesso (ACLs) ou papéis (RBAC/ABAC) consistentemente em toda a API ou aplicação, nunca deixando a segurança implícita.

CVE-2024-43456MEDIUMWindows Remote Desktop Services Tampering VulnerabilityEPSS 0.7%CVE-2016-4427—In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.EPSS 0.7%CVE-2020-2500CRITICALThis improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensEPSS 0.7%CVE-2023-28645MEDIUMSecure view can be bypassed by using internal API endpoint in Nextcloud richdocumentsEPSS 0.7%CVE-2026-2861MEDIUMFoswiki Changes/Viewfile/Oops information disclosureEPSS 0.7%CVE-2022-4331MEDIUMAn issue has been discovered in GitLab EE affecting all versions starting from 15.1 before 15.7.8, all versions starting from 15.8 before 15EPSS 0.7%CVE-2023-46712MEDIUMA improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacEPSS 0.7%CVE-2023-0319MEDIUMAn issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.EPSS 0.7%CVE-2017-16766—An improper access control vulnerability in synodsmnotify in Synology DiskStation Manager (DSM) before 6.1.4-15217 and before 6.0.3-8754-6 aEPSS 0.7%CVE-2025-30460HIGHA permissions issue was addressed by removing vulnerable code and adding additional checks. This issue is fixed in macOS Sequoia 15.4, macOSEPSS 0.7%CVE-2025-2218MEDIUMLoveCards LoveCardsV2 Setting other access controlEPSS 0.7%CVE-2025-43233CRITICALThis issue was addressed with improved access restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13EPSS 0.7%CVE-2024-1308HIGHWooCommerce Cloak Affiliate Links <= 1.0.33 - Missing Authorization to Unauthenticated Permalink ModificationEPSS 0.7%CVE-2023-22335—Improper access control vulnerability in SS1 Ver.13.0.0.40 and earlier and Rakuraku PC Cloud Agent Ver.2.1.8 and earlier allows a remote attEPSS 0.7%CVE-2024-45432HIGHOpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The EPSS 0.7%CVE-2024-10993MEDIUMCodezips Online Institute Management System manage_website.php unrestricted uploadEPSS 0.7%CVE-2022-4689HIGHImproper Access Control in usememos/memosEPSS 0.7%CVE-2023-6773MEDIUMCodeAstro POS and Inventory Management System User Creation register_account access controlEPSS 0.7%CVE-2024-13104MEDIUMD-Link DIR-816 A2 WiFi Settings form2AdvanceSetup.cgi access controlEPSS 0.7%CVE-2023-0661MEDIUMImproper access control in Devolutions Server allows an authenticated user to access unauthorized sensitive data. EPSS 0.7%