Falhas do tipo CWE-552

365 resultados

Arquivos ou diretórios acessíveis a terceiros

A aplicação ou servidor expõe arquivos ou diretórios com permissões insuficientes, permitindo que usuários não autorizados (locais ou remotos) leiam, modifiquem ou executem conteúdo sensível. O risco varia desde exposição de dados confidenciais até execução de código malicioso, dependendo do que está exposto e das permissões concedidas.

Exemplo

Um servidor web servindo a pasta /uploads com permissões 777, onde backup de banco de dados ou chaves privadas ficam armazenadas. Qualquer pessoa com acesso à rede (ou internet, se o servidor estiver exposto) consegue baixar esses arquivos. Outro cenário: arquivo de configuração com credenciais legível por todos em /etc/app/config.txt.

Como mitigar

Implemente o princípio do menor privilégio: defina permissões de arquivo e diretório restritivas (ex: 640, 750), revise listas de controle de acesso (ACLs), separe dados sensíveis de diretórios servidos publicamente, e audite regularmente permissões em produção usando ferramentas de varredura (find, stat, ou análise de ACLs).

CVE-2026-39871HIGHA path handling issue was addressed with improved logic. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5.EPSS 0.3%CVE-2021-3717A flaw was found in Wildfly. An incorrect JBOSS_LOCAL_USER challenge location when using the elytron configuration may lead to JBOSS_LOCAL_UEPSS 0.3%CVE-2020-25636MEDIUMA flaw was found in Ansible Base when using the aws_ssm connection plugin as there is no namespace separation for file transfers. Files are EPSS 0.3%CVE-2026-19987MEDIUMSourceCodester Best Employee Management System Profile exposure of information through directory listingEPSS 0.3%CVE-2026-34361CRITICALHAPI FHIR: Unauthenticated SSRF via /loadIG Chains with startsWith() Credential Leak for Authentication Token TheftEPSS 0.3%CVE-2021-21429MEDIUMCreation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven pluginEPSS 0.3%CVE-2025-12648MEDIUMWP-Members Membership Plugin <= 3.5.4.4 - Unauthenticated Information Exposure via Unprotected FilesEPSS 0.3%CVE-2025-58152MEDIUMFutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the inEPSS 0.3%CVE-2025-2222HIGHCWE-552: Files or Directories Accessible to External Parties vulnerability over https exists that could leak information and potential priviEPSS 0.3%CVE-2026-54457HIGHTensorZero: Arbitrary file read and SSRF in TensorZero Gateway's internal object storage endpointEPSS 0.3%CVE-2025-12747MEDIUMTainacan <= 1.0.0 - Unauthenticated Information ExposureEPSS 0.3%CVE-2025-14896HIGHdue to insufficient sanitazation in Vega’s `convert()` function when `safeMode` is enabled and the spec variable is an array. An attacker caEPSS 0.3%CVE-2026-42063MEDIUMiControl SOAP vulnerabilityEPSS 0.3%CVE-2024-7107MEDIUMDirectory Traversal in National Keep's CyberMathEPSS 0.3%CVE-2023-41566HIGHOA EKP v16 was discovered to contain an arbitrary download vulnerability via the component /ui/sys_ui_extend/sysUiExtend.do. This vulnerabilEPSS 0.3%CVE-2025-64185MEDIUMOpen OnDemand RPM packages create world writable locationsEPSS 0.3%CVE-2025-59976HIGHJunos Space: Arbitrary file download vulnerability in web interfaceEPSS 0.3%CVE-2025-11959HIGHImproper Access Control in Premierturk's Excavation Management Information SystemEPSS 0.3%CVE-2025-4634MEDIUMLocal File InclusionEPSS 0.3%CVE-2026-75413HIGHDocSys V2.02.80 is vulnerable to Any File Download. An attacker does not need to go through authentication to utilize the downloadDocEx.do iEPSS 0.3%