Falhas do tipo CWE-345

548 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-15147MEDIUMFive Star Restaurant Reservations < 2.7.23 - Unauthenticated Payment Bypass and Booking Confirmation via IDOREPSS 0.1%CVE-2022-0031MEDIUMCortex XSOAR: Local Privilege Escalation (PE) Vulnerability in Cortex XSOAR EngineEPSS 0.1%CVE-2026-88819MEDIUMIn Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID.EPSS 0.1%CVE-2026-84767MEDIUMWordPress BookIt plugin <= 2.6.0.3 - Bypass Vulnerability vulnerabilityEPSS 0.1%CVE-2026-44523CRITICALNote Mark: JWT Secret Weakness allows Full Account Takeover via token forgeryEPSS 0.1%CVE-2021-26403MEDIUMInsufficient checks in SEV may lead to a malicious hypervisor disclosing the launch secret potentially resulting in compromise of VM confideEPSS 0.1%CVE-2026-71576HIGHMulticluster-global-hub: multicluster-global-hub: manager trusts self-asserted evt.source() for leaf-hub identity in all status handlersEPSS 0.1%CVE-2026-68945HIGHAngular: Cache-Key Ambiguity in HttpTransferCache Leading to Cross-Request Response Reuse and State PoisoningEPSS 0.1%CVE-2022-2789MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, aEPSS 0.1%CVE-2026-52688HIGHRRSIGs with too few labels can lead to bypass of DNSSEC wildcard validationEPSS 0.1%CVE-2026-47696HIGHWWBN AVideo: Authenticated wallet credit bypass in AuthorizeNet processPayment endpointEPSS 0.1%CVE-2026-17011LOWNexter Blocks < 5.0.2 - Contributor+ Stored CSS InjectionEPSS 0.1%CVE-2026-85008LOWundici vulnerable to caching and replay of unsafe HTTP method responsesEPSS 0.1%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.1%CVE-2022-33861MEDIUMInsufficient verification of authenticity in IPPEPSS 0.1%CVE-2026-30603MEDIUMAn issue in the firmware update mechanism of Qianniao QN-L23PA0904 v20250721.1640 allows attackers to gain root access, install backdoors, aEPSS 0.1%CVE-2026-35659MEDIUMOpenClaw < 2026.3.22 - Unresolved Service Metadata Routing via Bonjour and DNS-SD DiscoveryEPSS 0.1%CVE-2022-42267HIGHNVIDIA GPU Display Driver for Windows contains a vulnerability where a regular user can cause an out-of-bounds read, which may lead to code EPSS 0.1%CVE-2026-83533MEDIUMWP Express Checkout < 2.4.9 - Unauthenticated Payment Bypass via wpec_process_paymentEPSS 0.1%CVE-2026-82215MEDIUMWC PayPay Gateway 0.5 - 0.9.3 - Unauthenticated Payment Bypass via Unverified WebhookEPSS 0.1%