Falhas do tipo CWE-502

2.653 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2022-23734HIGHDeserialization of Untrusted Data vulnerability in GitHub Enterprise Server leading to Remote Code ExecutionEPSS 2.0%CVE-2022-0573HIGHJFrog Artifactory before 7.36.1 and 6.23.41, is vulnerable to Insecure Deserialization of untrusted data which can lead to DoS, Privilege EsEPSS 2.0%CVE-2021-39321HIGHSassy Social Share 3.3.23 PHP Object InjectionEPSS 2.0%CVE-2022-3357HIGHSmart Slider 3 < 3.5.1.11 - PHP Object InjectionEPSS 2.0%CVE-2021-22855CRITICALSoar Cloud System Co., Ltd. HR Portal - Arbitrary Code ExecutionEPSS 2.0%CVE-2022-43019CRITICALOpenCATS v0.9.6 was discovered to contain a remote code execution (RCE) vulnerability via the getDataGridPager's ajax functionality.EPSS 2.0%CVE-2026-2113MEDIUMyuan1994 tpadmin WebUploader preview.php deserializationEPSS 2.0%CVE-2020-12015A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserializatEPSS 2.0%CVE-2026-35439HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 2.0%CVE-2016-8648HIGHIt was found that the Karaf container used by Red Hat JBoss Fuse 6.x, and Red Hat JBoss A-MQ 6.x, deserializes objects passed to MBeans via EPSS 2.0%CVE-2024-47072HIGHXStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input streamEPSS 2.0%CVE-2024-6327CRITICALProgress Telerik Report Server DeserializationEPSS 2.0%CVE-2020-11067HIGHDeserialization of Untrusted Data in TYPO3 CMSEPSS 2.0%CVE-2021-29485CRITICALRemote Code Execution Vulnerability in Session StorageEPSS 2.0%CVE-2026-40368HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-3360HIGHLearnPress < 4.1.7.2 - Unauthenticated PHP Object Injection via REST APIEPSS 2.0%CVE-2021-24280Redirection for Contact Form 7 < 2.3.4 - Authenticated PHP Object InjectionEPSS 2.0%CVE-2026-33110HIGHMicrosoft SharePoint Server Remote Code Execution VulnerabilityEPSS 2.0%CVE-2022-2436HIGHDownload Manager <= 3.2.49 - Authenticated (Contributor+) PHAR DeserializationEPSS 2.0%CVE-2023-38647CRITICALApache Helix: Deserialization vulnerability in Helix workflow and RESTEPSS 2.0%