Falhas do tipo CWE-441

159 resultados

Deputado Confuso (intermediário não intencional)

Ocorre quando um programa confiável é explorado para executar ações em nome de um atacante, porque não valida corretamente quem está pedindo e em qual contexto. O programa age como intermediário involuntário, abusando de seus privilégios para fazer algo que não deveria.

Exemplo

Um serviço web roda com permissões altas e aceita uma URL ou caminho como parâmetro sem validar a origem. Um atacante envia requisição malformada que o serviço interpreta como vindo de um usuário legítimo, causando dele mesmo deletar arquivos ou acessar dados sensíveis que o atacante sozinho não poderia.

Como mitigar

Valide rigorosamente a origem, contexto e intenção de cada requisição (quem está pedindo, de onde, e se tem direito). Implemente verificação de autenticação robusta, use tokens com escopo limitado (OAuth 2.0), e nunca confie apenas em parâmetros do usuário para tomar decisões de segurança ou privilégio.

CVE-2026-86115MEDIUMSim before 0.8.14 Confused Deputy in Tool URL Routing Mints an Internal Token for a User-Supplied /api/ PathEPSS 0.3%CVE-2026-12879MEDIUMCross-Tenant Data Exfiltration in Apigee via BigQuery Confused DeputyEPSS 0.3%CVE-2026-50022MEDIUMMetacat acts as unintended proxy to backend Apache SOLR engineEPSS 0.3%CVE-2026-24470HIGHSkipper Ingress Controller Allows Unauthorized Access to Internal Services via ExternalNameEPSS 0.3%CVE-2025-68944MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.EPSS 0.3%CVE-2026-73424MEDIUMAstro: Unauthenticated path override in the @astrojs/vercel ISR functionEPSS 0.3%CVE-2026-72640MEDIUMUnintended Proxy or Intermediary in Elastic Cloud on Kubernetes Leading to Cross-Namespace Secret DisclosureEPSS 0.3%CVE-2026-81303MEDIUMHawtio-operator: hawtio-operator: routes/custom-host confused-deputy via spec.routehostnameEPSS 0.3%CVE-2026-87442LOWConfused deputy in Prerender in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to pEPSS 0.3%CVE-2022-39349MEDIUMTasks.org vulnerable to data exfiltration by malicous app or adbEPSS 0.3%CVE-2026-87453MEDIUMConfused deputy in BackgroundFetch in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer procesEPSS 0.3%CVE-2025-64125CRITICALNuvation Energy nCloud Client-to-Client CommunicationEPSS 0.3%CVE-2026-53513CRITICALBetter Auth: Server-side request forgery via unvalidated OIDC endpoints on @better-auth/sso provider registrationEPSS 0.2%CVE-2026-77348HIGHWallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`EPSS 0.2%CVE-2026-49821HIGHFission: Cross-namespace Environment reference in Package allows build-time command execution and SA token exfiltrationEPSS 0.2%CVE-2026-16158HIGH@fastify/reply-from vulnerable to cross-upstream request routing via URL cache key collisionEPSS 0.2%CVE-2026-50169MEDIUMAngular Service Worker Policy-Bypass & Credential-Stripping VulnerabilitiesEPSS 0.2%CVE-2026-3160MEDIUMUnintended Proxy or Intermediary ('Confused Deputy') in GitLabEPSS 0.2%CVE-2026-48522MEDIUMPyJWKClient: missing scheme allowlist enables SSRF + token forgery via file://, ftp://, data: schemesEPSS 0.2%CVE-2026-73266HIGHClusterclaims-controller: confused deputy: tenant-controlled clusterclaim labels propagated to managedcluster, enabling cross-tenant managedclusterset joinEPSS 0.2%