Falhas do tipo CWE-502

2.648 resultados

Desserialização de dados não confiáveis

A aplicação converte dados recebidos de fontes externas (requisições, arquivos, rede) de volta para objetos em memória sem validar se o conteúdo é legítimo. Um atacante pode enviar dados malformados ou maliciosos que, ao serem desserializados, executam código arbitrário ou alteram o comportamento da aplicação.

Exemplo

Um servidor Java que desserializa objetos vindo de um cliente usando ObjectInputStream sem verificar a origem. Um atacante envia um objeto serializado contendo uma gadget chain que executa comandos do sistema operacional quando desserializado.

Como mitigar

Valide rigorosamente o tipo e estrutura dos dados antes de desserializar; use bibliotecas modernas que restringem quais classes podem ser desserializadas (com allowlists); considere alternativas como JSON com parsers estritamente tipados ao invés de serialização nativa de linguagem.

CVE-2024-22320CRITICALIBM Operational Decision Manager code executionEPSS 73.4%CVE-2018-0824HIGHA remote code execution vulnerability exists in "Microsoft COM for Windows" when it fails to properly handle serialized objects, aka "MicrosEPSS 73.2%KEVCVE-2023-36039HIGHMicrosoft Exchange Server Spoofing VulnerabilityEPSS 73.0%CVE-2020-5741HIGHDeserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.EPSS 72.9%KEVCVE-2021-21345MEDIUMXStream is vulnerable to a Remote Command Execution attackEPSS 72.3%CVE-2023-20864CRITICALVMware Aria Operations for Logs contains a deserialization vulnerability. An unauthenticated, malicious actor with network access to VMware EPSS 70.4%CVE-2022-26133CRITICALSharedSecretClusterAuthenticator in Atlassian Bitbucket Data Center versions 5.14.0 and later before 7.6.14, 7.7.0 and later prior to 7.17.6EPSS 70.4%CVE-2021-35215HIGHActionPluginBaseView Deserialization of Untrusted Data RCEEPSS 69.7%CVE-2019-17571CRITICALIncluded in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely exeEPSS 69.1%CVE-2022-38108HIGHSolarWinds Platform Deserialization of Untrusted DataEPSS 68.9%CVE-2023-6933HIGHBetter Search Replace <= 1.4.4 - Unauthenticated PHP Object InjectionEPSS 68.0%CVE-2023-38204CRITICALBypass APSB23-41 (CVE-2023-38203) - Pre-Auth RCE ColdFusion 2021 Update 8EPSS 66.2%CVE-2021-42127A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execuEPSS 65.8%CVE-2021-40865Unsafe Pre-Authentication Deserialization In WorkersEPSS 65.6%CVE-2024-54676CRITICALApache OpenMeetings: Deserialisation of untrusted data in cluster modeEPSS 64.9%CVE-2023-44350CRITICALColdFusion | Deserialization of Untrusted Data (CWE-502)EPSS 64.6%CVE-2023-39475CRITICALInductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 64.1%CVE-2022-23302HIGHDeserialization of untrusted data in JMSSink in Apache Log4j 1.xEPSS 63.6%CVE-2023-39473HIGHInductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution VulnerabilityEPSS 62.5%CVE-2022-21445CRITICALVulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported vEPSS 62.5%KEV