Falhas do tipo CWE-348

74 resultados

Confiança em fonte menos confiável

A aplicação aceita dados ou comandos de uma origem com menor nível de confiança (como entrada do usuário, rede não segura ou terceiros) e os trata com a mesma confiança de fontes seguras (variáveis internas, administrador). Isso permite que um atacante injete ou manipule dados que o programa deveria validar rigorosamente.

Exemplo

Um sistema de e-commerce confia diretamente no identificador de usuário enviado no parâmetro URL para recuperar dados da conta, sem verificar se quem fez a requisição é realmente aquele usuário. Um atacante muda o ID na URL e acessa contas de outros clientes.

Como mitigar

Sempre validar, sanitizar e autorizar dados de fontes externas antes de usá-los em operações sensíveis. Implementar controles de acesso (autenticação e autorização) que verificam se quem requisita tem permissão real, não apenas confiar em parâmetros do cliente.

CVE-2026-63770HIGHGlance 0.8.5 IP Spoofing Authentication Brute-Force Protection BypassEPSS 0.3%CVE-2026-61682CRITICALkcp front-proxy does not strip inbound X-Remote-* identity headers, allowing any authenticated client to inject groups/warrants and impersonate system:masters in any workspaceEPSS 0.3%CVE-2026-57942MEDIUMLibreTranslate - IP Spoofing via X-Forwarded-For HeaderEPSS 0.3%CVE-2026-26927MEDIUMURL (HTTP Origin) call location spoofing in Szafir SDK WebEPSS 0.3%CVE-2022-44593LOWWordPress Solid Security plugin <= 9.3.1 - IP Spoofing Leading to Denial of Service vulnerabilityEPSS 0.3%CVE-2024-0789MEDIUMWP Maintenance <= 6.1.9.2 - IP Spoofing to Maintenance Mode BypassEPSS 0.3%CVE-2024-6171MEDIUMUnlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.112 - IP Address Spoofing to Antispam BypassEPSS 0.2%CVE-2025-15154MEDIUMPbootCMS Header handle.php get_user_ip less trusted sourceEPSS 0.2%CVE-2022-4536MEDIUMIP Vault – WP Firewall <= 1.1 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-43634HIGHHestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP HeaderEPSS 0.2%CVE-2026-46415HIGHCaddy Defender trusted proxy client IP bypassEPSS 0.2%CVE-2025-13694MEDIUMAA Block country <= 1.0.1 - Unauthenticated IP Address Spoofing via X-Forwarded-For HeaderEPSS 0.2%CVE-2022-4529MEDIUMSecurity, Antivirus, Firewall – S.A.F <= 2.3.5 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-44183CRITICALCleanuparr: X-Forwarded-For leftmost parsing allows remote unauthenticated admin takeover when reverse-proxy mode is enabledEPSS 0.2%CVE-2022-4533MEDIUMLimit Login Attempts Plus <= 1.1.0 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-48772CRITICALProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules.client_addr ACLEPSS 0.2%CVE-2022-4532MEDIUMLOGIN AND REGISTRATION ATTEMPTS LIMIT<= 2.1 - IP Address Spoofing to Protection Mechanism BypassEPSS 0.2%CVE-2026-9561HIGHEclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP addrEPSS 0.2%CVE-2026-90711CRITICALproxy-addr vulnerable to IP spoofing via IPv4-mapped IPv6 trust subnetEPSS 0.2%CVE-2020-37248MEDIUMOfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle aEPSS 0.2%