Falhas do tipo CWE-290

607 resultados

Autenticação vulnerável a falsificação de identidade

Ocorre quando o sistema implementa mecanismos de autenticação de forma incorreta, permitindo que um atacante se passe por outro usuário sem fornecer credenciais válidas. A falha geralmente está em lógica fraca de validação de identidade, como confiar em dados facilmente manipuláveis (headers HTTP, cookies não assinados) ou em esquemas de autenticação incompletos que não verificam adequadamente quem está fazendo a requisição.

Exemplo

Um aplicativo web que valida login apenas verificando se existe um cookie com o nome 'user_id=123', sem assinatura criptográfica. Um atacante pode simplesmente adicionar esse cookie em sua requisição e o sistema o autenticará como o usuário 123. Outro caso comum: APIs que usam IP de origem como forma de autenticação, facilmente spoofada.

Como mitigar

Implemente autenticação robusta baseada em padrões estabelecidos (OAuth 2.0, JWT com assinatura, sessões server-side com tokens opacos). Valide identidade em cada requisição através de mecanismos criptográficos. Nunca confie unicamente em dados do cliente (headers customizados, cookies não assinados) como prova de identidade; sempre verifique contra estado confiável no servidor.

CVE-2023-29147—In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier EPSS 0.3%CVE-2025-29621HIGHFrancois Jacquet RosarioSIS v12.0.0 was discovered to contain a content spoofing vulnerability in the Theme configuration under the My PrefeEPSS 0.3%CVE-2024-9391MEDIUMA user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may EPSS 0.3%CVE-2025-65046LOWMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.3%CVE-2023-34160MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2026-15640CRITICALAuthentication Bypass via SAML Response ManipulationEPSS 0.3%CVE-2023-34158MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2023-34167MEDIUMVulnerability of spoofing trustlists of Huawei desktop.Successful exploitation of this vulnerability can cause third-party apps to hide app EPSS 0.3%CVE-2025-30142HIGHAn issue was discovered on G-Net Dashcam BB GONX devices. Bypassing of Device Pairing can occur. It uses MAC address verification as the solEPSS 0.3%CVE-2026-46356MEDIUMFleet: IP spoofing allows bypassing API rate limitingEPSS 0.3%CVE-2025-30110MEDIUMOn IROAD X5 devices, a Bypass of Device Pairing can occur via MAC Address Spoofing. The dashcam's pairing mechanism relies solely on MAC addEPSS 0.3%CVE-2024-8399MEDIUMWebsites could utilize Javascript links to spoof URL addresses in the Focus navigation bar This vulnerability affects Focus for iOS < 130.EPSS 0.3%CVE-2026-90447HIGHA routing rule selects between two different authentication mechanisms for the same downstream service based on the value of a client-suppliEPSS 0.3%CVE-2026-53849HIGHOpenClaw < 2026.5.7 - Privilege Escalation via Mutable Discord Display Names in allowFromEPSS 0.3%CVE-2026-31889HIGHShopware has a potential take over of app credentialsEPSS 0.3%CVE-2026-27089HIGHWordPress WpTravelly plugin <= 2.1.7 - Bypass Vulnerability vulnerabilityEPSS 0.3%CVE-2024-1524HIGHA local user can be impersonated when using federated authentication with Silent JIT Provisioning.EPSS 0.3%CVE-2024-5812LOWSmart Rule Overwrite Bypass in BeyondInsight PasswordSafeEPSS 0.3%CVE-2026-47737HIGHPuma PROXY Protocol v1 Accepts Repeated Protocol Headers on Persistent ConnectionsEPSS 0.3%CVE-2026-82530MEDIUMIP2Location Country Blocker < 2.45.0 Access Control Bypass via X-Real-IP HeaderEPSS 0.3%