Falhas do tipo CWE-494

187 resultados

Elevação de privilégio

A aplicação não valida corretamente permissões ou contexto de segurança, permitindo que um usuário com privilégios baixos execute ações reservadas a administradores ou usuários com acesso mais elevado. É perigoso porque quebra o modelo de controle de acesso e expõe funcionalidades críticas.

Exemplo

Um usuário comum consegue acessar a API de administração porque o servidor valida apenas a presença de um token válido, ignorando o campo de 'role' contido nele; ou um programa SUID não revoga permissões root antes de executar código fornecido pelo usuário, permitindo leitura de arquivos sensíveis.

Como mitigar

Implemente verificação rigorosa de permissões em toda ação sensível (autorização não apenas autenticação), use listas de controle de acesso (ACL) explícitas, aplique princípio do menor privilégio e audite chamadas privilegiadas. Teste com usuários em papéis baixos para confirmar bloqueios.

CVE-2023-5630MEDIUM A CWE-494: Download of Code Without Integrity Check vulnerability exists that could allow a privileged user to install an untrusted firmwEPSS 0.3%CVE-2020-7817MEDIUMMyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in doEPSS 0.3%CVE-2024-28878CRITICALIOSIX IO-1020 Micro ELD Download of Code Without Integrity CheckEPSS 0.3%CVE-2025-7620HIGHDSIC|Cross-browser Components for Official Document Creation - Remote Code ExecutionEPSS 0.3%CVE-2023-45799HIGHMLSoft TCO!stream Remote Code Execution VulnerabilityEPSS 0.3%CVE-2024-39348HIGHDownload of code without integrity check vulnerability in AirPrint functionality in Synology Router Manager (SRM) before 1.2.5-8227-11 and 1EPSS 0.3%CVE-2026-92128HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a JAR file specified by URL twice, confirming the approval of theEPSS 0.3%CVE-2023-41921CRITICALDownload of Code Without Integrity Check in Kiloview P1/P2 devicesEPSS 0.3%CVE-2024-33118HIGHLuckyFrameWeb v3.5.2 was discovered to contain an arbitrary read vulnerability via the fileDownload method in class com.luckyframe.project.cEPSS 0.2%CVE-2026-59286HIGHSpring for GraphQL loads Untrusted Resources in GraphiQL supportEPSS 0.2%CVE-2026-9037CRITICALDownload of code without integrity check in XCharge C6EPSS 0.2%CVE-2022-37908MEDIUMAn authenticated attacker can impact the integrity of the ArubaOS bootloader on 7xxx series controllers. Successful exploitation can compromEPSS 0.2%CVE-2025-1058HIGHCWE-494: Download of Code Without Integrity Check vulnerability exists that could render the device inoperable when malicious firmware is doEPSS 0.2%CVE-2026-49241HIGHAngular: Multiple Remote Code Execution Vulnerabilities in Angular Language Service VS Code ExtensionEPSS 0.2%CVE-2025-55582MEDIUMD-Link DCS-825L firmware v1.08.01 contains a vulnerability in the watchdog script `mydlink-watch-dog.sh`, which blindly respawns binaries suEPSS 0.2%CVE-2025-35115CRITICALAgiloft insecure download of system packagesEPSS 0.2%CVE-2026-45058CRITICALelecterm: Import unsafe bookmark data could lead to unsafe operation when click local type bookmarkEPSS 0.2%CVE-2023-28317MEDIUMA vulnerability has been discovered in Rocket.Chat, where editing messages can change the original timestamp, causing the UI to display messEPSS 0.2%CVE-2026-34841CRITICALAxios npm Supply Chain Incident Impacting @usebruno/cliEPSS 0.2%CVE-2024-55459MEDIUMAn issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar file through the get_fEPSS 0.2%