Falhas do tipo CWE-345

551 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-11836LOWProduction Debug-Unlock Token Verification Missing Device BindingEPSS 0.1%CVE-2026-92138MEDIUMThe OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callback` URL from the suEPSS 0.1%CVE-2026-26327HIGHOpenClaw allows unauthenticated discovery TXT records to steer routing and TLS pinningEPSS 0.1%CVE-2026-54174HIGHmelange: Incomplete package integrity verification allows data section substitutionEPSS 0.1%CVE-2025-59323HIGHCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to validate the integrity of the DataStore, a non-partitioned filesystem, respoEPSS 0.1%CVE-2022-48431MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 in some cases, Gradle and Maven projects could be imported without the “Trust Project” confirmationEPSS 0.1%CVE-2026-21078MEDIUMInsufficient verification of data authenticity in Smart Switch trouble scanning mode prior to version 3.7.72.6 allows adjacent attackers to EPSS 0.1%CVE-2023-20570LOWInsufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bEPSS 0.1%CVE-2026-91017LOWRobokassa payment gateway for Woocommerce < 1.8.9 - Unauthenticated Payment Bypass via Forged JWT CallbackEPSS 0.1%CVE-2026-89050MEDIUMQuads Ads Manager for Google AdSense < 3.0.5 - Subscriber+ Ad-Selling Payment Bypass via Unverified Success Return URLEPSS 0.1%CVE-2026-79621MEDIUMCatalogX < 6.1.3 - Unauthenticated Email Content Injection via Shared TransientEPSS 0.1%CVE-2026-48096MEDIUMOpenFGA: Cache-key delimiter injection in openfga/openfga shared-iterator and v2 iterator caches enables intra-store authorization-decision poisoningEPSS 0.1%CVE-2026-53900MEDIUMCookie injection was possible when opening a PDF linkEPSS 0.1%CVE-2023-21441HIGHInsufficient Verification of Data Authenticity vulnerability in Routine prior to versions 2.6.30.6 in Android Q(10), 3.1.21.10 in Android R(EPSS 0.1%CVE-2026-92422MEDIUMMeow Gallery < 5.5.5 - Unauthenticated Arbitrary Shortcode Execution via load_gallery_collection REST RouteEPSS 0.1%CVE-2026-18044LOWEstatik Real Estate Plugin < 4.3.4 - Unauthenticated Arbitrary-Recipient Mail Relay via Signed-Value MismatchEPSS 0.1%CVE-2026-14663MEDIUMPostgreSQL pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartextEPSS 0.1%CVE-2026-22703MEDIUMCosign verification accepts any valid Rekor entry under certain conditionsEPSS 0.1%CVE-2026-53899MEDIUMCross-origin cookies could be leaked when opening a PDF linkEPSS 0.1%CVE-2026-75509MEDIUMjoserfc claim-validation bypass via array-typed single-string claims (iss/sub/jti)EPSS 0.1%