Falhas do tipo CWE-345

557 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2024-24557MEDIUMMoby classic builder cache poisoningEPSS 0.3%CVE-2026-11901MEDIUMWP Hotel Booking <= 2.3.1 - Unauthenticated Insufficient Verification of Data Authenticity to Payment Bypass via PayPal IPN HandlerEPSS 0.3%CVE-2024-1321MEDIUMEventPrime – Events Calendar, Bookings and Tickets <= 3.4.2 - Unauthenticated Booking Payment BypassEPSS 0.3%CVE-2026-45069HIGHSymfony: OidcTokenHandler Accepts JWTs Missing aud/iss/exp ClaimsEPSS 0.3%CVE-2025-54792CRITICALLocalSend is Vulnerable to Man-in-the-Middle Attacks, Leading to File InterceptionEPSS 0.3%CVE-2025-5320MEDIUMgradio-app gradio CORS is_valid_origin privilege escalationEPSS 0.3%CVE-2026-28454HIGHOpenClaw < 2026.2.2 - Authorization Bypass via Unauthenticated Telegram WebhookEPSS 0.3%CVE-2026-44725MEDIUMEMQX: Stale plugins allow grants amplify a compromised admin/API key to remote code executionEPSS 0.3%CVE-2026-1195LOWMineAdmin JWT Token refresh data authenticityEPSS 0.3%CVE-2026-62215MEDIUMOpenClaw < 2026.6.5 Authentication Bypass via HTTP CanvasEPSS 0.3%CVE-2024-10237HIGHSMC BMC Firmware Image Authentication Design IssueEPSS 0.2%CVE-2026-47155MEDIUMvLLM: Artifact Pin Decay in vLLM allows pinned deployments to load unpinned code, weights, and processorsEPSS 0.2%CVE-2026-30851HIGHCaddy forward_auth copy_headers Does Not Strip Client-Supplied Headers, Allowing Identity Injection and Privilege EscalationEPSS 0.2%CVE-2022-34471MEDIUMWhen downloading an update for an addon, the downloaded addon update's version was not verified to match the version selected from the manifEPSS 0.2%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2026-68554LOWCoturn: STUN attributes after MESSAGE-INTEGRITY are processed, letting on-path attackers modify authenticated TURN requestsEPSS 0.2%CVE-2026-54781HIGHCoreWCF: SAML SubjectConfirmation methods and holder-of-key proof keys are not enforcedEPSS 0.2%CVE-2026-6967HIGHMissing Delegated Metadata Validation in awslabs/toughEPSS 0.2%CVE-2025-5832MEDIUMPioneer DMH-WT7600NEX Software Update Signing Insufficient Verification of Data Authenticity VulnerabilityEPSS 0.2%CVE-2026-27700HIGHHono is Vulnerable to Authentication Bypass by IP Spoofing in AWS Lambda ALB conninfoEPSS 0.2%