Falhas do tipo CWE-345

555 resultados

Verificação insuficiente de autenticidade de dados

A aplicação recebe dados de fontes externas (rede, arquivo, entrada do usuário) mas não valida adequadamente se eles realmente vieram de quem diz vir ou se não foram alterados no caminho. Isso permite que um atacante forje, intercepte ou modifique dados sem que o sistema detecte, comprometendo integridade e confiança.

Exemplo

Um serviço REST que confia cegamente em um campo 'user_id' vindo do cliente, sem verificar assinatura ou token, permitindo que alguém mude a URL para acessar dados de outro usuário. Ou um arquivo de configuração lido sem validar sua hash, permitindo execução de código malicioso se o arquivo for corrompido.

Como mitigar

Use mecanismos criptográficos de autenticação (HMAC, assinatura digital, certificados TLS) para garantir a origem e integridade dos dados. No lado do servidor, nunca confie em identificadores ou claims do cliente — valide contra seu próprio estado autorizado (sessão, JWT assinado, etc).

CVE-2026-45674HIGHNetty Vulnerable to DNS Cache Poisoning via Missing Bailiwick Checks in CNAME RecordsEPSS 0.3%CVE-2026-30223HIGHOliveTin: JWT Audience Validation Bypass in Local Key and HMAC ModesEPSS 0.3%CVE-2026-7792MEDIUMWPForms <= 1.10.0.4 - Unauthenticated Insufficient Verification of Data Authenticity via PayPal Commerce Webhook EndpointEPSS 0.3%CVE-2025-12245MEDIUMchatwoot Widget IFrameHelper.js initPostMessageCommunication origin validationEPSS 0.3%CVE-2025-27558CRITICALIEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or EPSS 0.3%CVE-2026-53961MEDIUMDiscourse: Forged AWS SNS bounce notifications can disable a targeted user's email (missing TopicArn binding)EPSS 0.3%CVE-2023-23941HIGHSwagPayPal payment not sent to PayPal correctlyEPSS 0.3%CVE-2026-23656MEDIUMWindows App Installer Spoofing VulnerabilityEPSS 0.3%CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2022-37928HIGHInsufficient Verification of Data Authenticity vulnerability in Hewlett Packard Enterprise HPE Nimble Storage Hybrid Flash Arrays and NimbleEPSS 0.3%CVE-2022-37008HIGHThe recovery module has a vulnerability of bypassing the verification of an update package before use. Successful exploitation of this vulneEPSS 0.3%CVE-2022-27513HIGHRemote desktop takeover via phishingEPSS 0.3%CVE-2024-34354MEDIUMCMSaasStarter: JWT Token Not Verified on Server SessionEPSS 0.3%CVE-2020-3174MEDIUMCisco NX-OS Software Anycast Gateway Invalid ARP VulnerabilityEPSS 0.3%CVE-2026-27510MEDIUMUnitree Go2 Mobile Program Tampering Enables Root RCEEPSS 0.3%CVE-2019-3875MEDIUMA vulnerability was found in keycloak before 6.0.2. The X.509 authenticator supports the verification of client certificates through the CRLEPSS 0.3%CVE-2026-58593HIGHNodeBB - ActivityPub Author Spoofing via Unvalidated attributedTo Mapped to Local UserEPSS 0.3%CVE-2022-46139MEDIUMTP-Link TL-WR940N V4 3.16.9 and earlier allows authenticated attackers to cause a Denial of Service (DoS) via uploading a crafted firmware iEPSS 0.3%CVE-2026-53516HIGHBetter Auth: Account takeover via OAuth auto-link to unverified pre-registered emailEPSS 0.3%CVE-2026-30798HIGHRustDesk Client Accepts Unauthenticated stop-service Command via Strategy PayloadEPSS 0.3%