Falhas do tipo CWE-424

39 resultados

Proteção inadequada de caminhos alternativos

O software protege um caminho ou recurso principal, mas deixa desprotegido um caminho alternativo que leva ao mesmo destino. Um atacante contorna as validações da rota esperada usando uma entrada equivalente que não foi validada adequadamente.

Exemplo

Uma aplicação bloqueia acesso a '/admin/painel' com autenticação, mas não valida '/admin/../painel' ou a codificação alternativa da URL. O atacante usa o caminho alternativo e bypassa a proteção porque a validação foi implementada apenas para o caminho canônico.

Como mitigar

Normalize todas as entradas (URLs, caminhos de arquivo, paths) antes de validar, removendo caracteres especiais e resolvendo referências relativas (/../). Aplique as mesmas regras de autenticação e autorização para qualquer variação de acesso ao recurso sensível, não apenas a forma esperada.

CVE-2024-3459HIGHKioWare for Windows (versions all through 8.34) allows to escape the environment by downloading PDF files, which then by default are opened EPSS 0.3%CVE-2025-0113MEDIUMCortex XDR Broker VM: Unauthorized Access to Broker VM Docker ContainersEPSS 0.3%CVE-2025-46654MEDIUMCodiMD through 2.2.0 has a CSP-based protection mechanism against XSS through uploaded JavaScript content, but it can be bypassed by uploadiEPSS 0.3%CVE-2025-46655MEDIUMCodiMD through 2.5.4 has a CSP-based protection mechanism against XSS through uploaded SVG documents containing JavaScript, but it can be byEPSS 0.2%CVE-2023-5165HIGHDocker Desktop before 4.23.0 allows Enhanced Container Isolation bypass via debug shellEPSS 0.2%CVE-2023-0629HIGHDocker Desktop before 4.17.0 allows an unprivileged user to bypass Enhanced Container Isolation restrictions via the raw Docker socket and launch privileged containersEPSS 0.2%CVE-2024-8781HIGHContainer Escape Vulnerability in TR7's Application Security Platform (ASP)EPSS 0.2%CVE-2025-49162MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK allow file overwrite via TFTP because a remote filename with a space character alloEPSS 0.2%CVE-2023-46176MEDIUMIBM MQ privilege escalationEPSS 0.2%CVE-2023-52952CRITICALA vulnerability has been identified in HiMed Cockpit 12 pro (J31032-K2017-H259) (All versions >= V11.5.1 < V11.6.2), HiMed Cockpit 14 pro+ (EPSS 0.2%CVE-2025-6250HIGHPrivilege Management for Windows - Elevation of PrivilegeEPSS 0.2%CVE-2025-49163MEDIUMArris VIP1113 devices through 2025-05-30 with KreaTV SDK allow booting an arbitrary image via a crafted /usr/bin/gunzip file.EPSS 0.2%CVE-2026-0237HIGHPrisma Browser: Improperly Restricted Automation Bridge Allows Security BypassEPSS 0.1%CVE-2025-4617LOWPrisma Browser: Insufficient Policy Enforcement Vulnerability in Prisma BrowserEPSS 0.1%CVE-2026-4270MEDIUMAWS API MCP File Access Restriction BypassEPSS 0.1%CVE-2026-37008HIGHCrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVEEPSS 0.1%CVE-2022-24932MEDIUMImproper Protection of Alternate Path vulnerability in Setup wizard process prior to SMR Mar-2022 Release 1 allows physical attacker packageEPSS 0.1%CVE-2022-28782MEDIUMImproper access control vulnerability in Contents To Window prior to SMR May-2022 Release 1 allows physical attacker to install package befoEPSS 0.1%CVE-2026-0268MEDIUMPrisma Access Agent: Local Authenticated VPN Enforcement Bypass on LinuxEPSS 0.1%