Falhas do tipo CWE-552

362 resultados

Arquivos ou diretórios acessíveis a terceiros

A aplicação ou servidor expõe arquivos ou diretórios com permissões insuficientes, permitindo que usuários não autorizados (locais ou remotos) leiam, modifiquem ou executem conteúdo sensível. O risco varia desde exposição de dados confidenciais até execução de código malicioso, dependendo do que está exposto e das permissões concedidas.

Exemplo

Um servidor web servindo a pasta /uploads com permissões 777, onde backup de banco de dados ou chaves privadas ficam armazenadas. Qualquer pessoa com acesso à rede (ou internet, se o servidor estiver exposto) consegue baixar esses arquivos. Outro cenário: arquivo de configuração com credenciais legível por todos em /etc/app/config.txt.

Como mitigar

Implemente o princípio do menor privilégio: defina permissões de arquivo e diretório restritivas (ex: 640, 750), revise listas de controle de acesso (ACLs), separe dados sensíveis de diretórios servidos publicamente, e audite regularmente permissões em produção usando ferramentas de varredura (find, stat, ou análise de ACLs).

CVE-2022-45129HIGHPayara before 2022-11-04, when deployed to the root context, allows attackers to visit META-INF and WEB-INF, a different vulnerability than EPSS 1.4%CVE-2022-2357WSM Downloader <= 1.4.0 - Unauthenticated Arbitrary File DownloadEPSS 1.4%CVE-2023-31066CRITICALApache InLong: Insecure direct object references for inlong sourcesEPSS 1.4%CVE-2024-21403CRITICALMicrosoft Azure Kubernetes Service Confidential Container Elevation of Privilege VulnerabilityEPSS 1.3%CVE-2020-11642HIGHSiteManager Denial of Service via Local File Inclusion VulnerabilityEPSS 1.3%CVE-2021-32833HIGHUnauthenticated file read in Emby ServerEPSS 1.3%CVE-2023-29450HIGHUnauthorized limited filesystem access from preprocessingEPSS 1.3%CVE-2023-31064HIGHApache InLong: Insecurity direct object references cancelling applicationsEPSS 1.2%CVE-2024-31141MEDIUMApache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProviderEPSS 1.2%CVE-2020-11641HIGHSiteManager Local File Inclusion VulnerabilityEPSS 1.2%CVE-2023-39480MEDIUMSofting Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation VulnerabilityEPSS 1.2%CVE-2022-32143HIGHCODESYS runtime system prone to directory accesEPSS 1.2%CVE-2025-66389HIGHGitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to feEPSS 1.2%CVE-2020-4075MEDIUMArbitrary file read via window-open IPC in ElectronEPSS 1.2%CVE-2021-25004SEUR Oficial < 1.7.2 - Admin+ Arbitrary File DownloadEPSS 1.2%CVE-2021-20182A privilege escalation flaw was found in openshift4/ose-docker-builder. The build container runs with high privileges using a chrooted envirEPSS 1.1%CVE-2018-1079HIGHpcs before version 0.9.164 and 0.10 is vulnerable to a privilege escalation via authorized user malicious REST call. The REST interface of tEPSS 1.1%CVE-2025-4807MEDIUMSourceCodester Online Student Clearance System exposure of information through directory listingEPSS 1.1%CVE-2022-35235MEDIUMWordPress WPide plugin <= 2.6 - Authenticated Arbitrary File Read vulnerabilityEPSS 1.1%CVE-2021-3856ClassLoaderTheme and ClasspathThemeResourceProviderFactory allows reading any file available as a resource to the classloader. By sending reEPSS 1.1%