Falhas do tipo CWE-348

74 resultados

Confiança em fonte menos confiável

A aplicação aceita dados ou comandos de uma origem com menor nível de confiança (como entrada do usuário, rede não segura ou terceiros) e os trata com a mesma confiança de fontes seguras (variáveis internas, administrador). Isso permite que um atacante injete ou manipule dados que o programa deveria validar rigorosamente.

Exemplo

Um sistema de e-commerce confia diretamente no identificador de usuário enviado no parâmetro URL para recuperar dados da conta, sem verificar se quem fez a requisição é realmente aquele usuário. Um atacante muda o ID na URL e acessa contas de outros clientes.

Como mitigar

Sempre validar, sanitizar e autorizar dados de fontes externas antes de usá-los em operações sensíveis. Implementar controles de acesso (autenticação e autorização) que verificam se quem requisita tem permissão real, não apenas confiar em parâmetros do cliente.

CVE-2025-27913LOWPassbolt API before 5, if the server is misconfigured (with an incorrect installation process and disregarding of Health Check results), canEPSS 0.2%CVE-2026-59897MEDIUMHono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplicationEPSS 0.2%CVE-2026-54289MEDIUMHono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the restEPSS 0.2%CVE-2025-24856MEDIUMAn issue was discovered in the oidc (aka OpenID Connect Authentication) extension before 4.0.0 for TYPO3. The account linking logic allows aEPSS 0.2%CVE-2026-33690MEDIUMAVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()EPSS 0.2%CVE-2025-53522MEDIUMMovable Type contains an issue with use of less trusted source. If exploited, tampered email to reset a password may be sent by a remote unaEPSS 0.2%CVE-2026-25552MEDIUMGhost CLI < 1.30.1 IP Spoofing via X-Forwarded-For HeaderEPSS 0.2%CVE-2025-1245MEDIUMBypass Connection Restriction Vulnerability in Hitachi Ops Center AnalyzerEPSS 0.2%CVE-2025-47149MEDIUMThe optional feature 'Anti-Virus & Sandbox' of i-FILTER contains an issue with improper pattern file validation. If exploited, the product mEPSS 0.2%CVE-2026-62987MEDIUMFabio - Incomplete fix for CVE-2025-48865: operator-configured trust headers (clientip/tls/requestid) still strippable via the Connection headerEPSS 0.2%CVE-2026-90679MEDIUMForgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not EPSS 0.2%CVE-2024-54840MEDIUMPVWA (Password Vault Web Access) in CyberArk Privileged Access Manager Self-Hosted before 14.4 does not properly address environment issues EPSS 0.2%CVE-2026-59999MEDIUMIn sshd in OpenSSH before 10.4, DisableForwarding=yes was supposed to take precedence over PermitTunnel=yes, but did not.EPSS 0.2%CVE-2026-61589MEDIUMdjust: WebSocket/runtime reconstructed request omits the client Host, causing host/subdomain TenantResolvers to misresolve the tenant on the live pathEPSS 0.2%CVE-2026-22201MEDIUMwpDiscuz before 7.6.47 - IP Address Spoofing in getIP()EPSS 0.2%CVE-2026-46466LOWDell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1EPSS 0.2%CVE-2025-47424HIGHRetool (self-hosted) before 3.196.0 allows Host header injection. When the BASE_DOMAIN environment variable is not set, the HTTP host headerEPSS 0.2%CVE-2025-69240HIGHHeader Poisoning in Raytha CMSEPSS 0.1%CVE-2026-16272CRITICALClient IP Spoofing via Untrusted HTTP Headers in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS ModuleEPSS 0.1%CVE-2026-12249CRITICALCanonical ADSys Trust Store Poisoning via Plaintext HTTP Certificate Auto-EnrollmentEPSS 0.1%