Falhas do tipo CWE-548

60 resultados

Exposição de Informações por Listagem de Diretório

Ocorre quando o servidor web lista o conteúdo de um diretório automaticamente, exibindo arquivos e pastas quando não há um arquivo índice (como index.html). Um atacante acessa uma URL de diretório e vê todos os arquivos disponíveis, podendo descobrir backups, arquivos de configuração, código-fonte ou outros ativos sensíveis não intencionados para exposição pública.

Exemplo

Um desenvolvedor carrega assets em /app/resources/ mas esquece de criar um index.html. Ao acessar https://exemplo.com/app/resources/, o servidor Apache com autoindex ativado lista todos os arquivos: backup.sql, config.json com credenciais, e versões antigas do código — tudo visível para qualquer um.

Como mitigar

Desative a listagem automática de diretórios no servidor (DirectoryIndex desativado no Apache, autoindex off, ou equivalente no Nginx). Coloque um index.html ou index.php em cada diretório público, ou restrinja acesso via permissões de arquivo e regras de firewall. Valide regularmente com varreduras que tentam acessar diretórios conhecidos.

CVE-2025-27452MEDIUMCVE-2025-27452EPSS 0.4%CVE-2025-45320HIGHA Directory Listing Vulnerability was found in the /osms/Requester/ directory of the Kashipara Online Service Management Portal V1.0.EPSS 0.4%CVE-2024-45096MEDIUMIBM Aspera Faspex information disclosureEPSS 0.4%CVE-2025-32750HIGHDell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory Listing vulnerability. An unauthenticateEPSS 0.4%CVE-2022-30625MEDIUMChcnav - P5E GNSS Directory listingEPSS 0.3%CVE-2024-35113MEDIUMIBM Control Center information disclosureEPSS 0.3%CVE-2026-82775MEDIUMAn exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. AccesEPSS 0.3%CVE-2024-28766LOWIBM Security Directory Integrator information disclosureEPSS 0.3%CVE-2026-19987MEDIUMSourceCodester Best Employee Management System Profile exposure of information through directory listingEPSS 0.3%CVE-2025-27906MEDIUMIBM Content Navigator information disclosureEPSS 0.3%CVE-2025-28170HIGHGrandstream Networks GXP1628 <=1.0.4.130 is vulnerable to Incorrect Access Control. The device is configured with directory listing enabled,EPSS 0.3%CVE-2024-56464LOWIBM QRadar SIEM is affected by an information disclosure vulnerabilityEPSS 0.3%CVE-2026-50233MEDIUMLyrion Music Server 9.2.0 Arbitrary Directory ListingEPSS 0.3%CVE-2025-1138MEDIUMIBM Information Server information disclosureEPSS 0.3%CVE-2025-62396MEDIUMMoodle: router (r.php) could expose application directoriesEPSS 0.3%CVE-2026-82778MEDIUMAn exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may alloEPSS 0.3%CVE-2026-41933MEDIUMVvveb < 1.0.8.3 Directory Listing Information DisclosureEPSS 0.2%CVE-2025-2827MEDIUMIBM Sterling File Gateway information disclosureEPSS 0.2%CVE-2023-38265MEDIUMImproper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]EPSS 0.2%CVE-2025-23378LOWDell PowerScale OneFS, versions 9.4.0.0 through 9.10.0.0, contains an exposure of information through directory listing vulnerability. A lowEPSS 0.2%