Falhas do tipo CWE-59

823 resultados

Seguimento de links simbólicos (symlink)

A aplicação segue links simbólicos sem validação, permitindo que um atacante redirecione operações de arquivo para locais não autorizados. Isso pode resultar em leitura, modificação ou exclusão de arquivos sensíveis fora do diretório esperado.

Exemplo

Um servidor web processa uploads em /tmp/uploads/, mas não verifica se os caminhos são links simbólicos. Um atacante cria um symlink em /tmp/uploads/config que aponta para /etc/passwd, e a aplicação sobrescreve o arquivo de senhas do sistema.

Como mitigar

Use funções que resolvem caminhos canônicos (realpath em C, Path.toRealPath() em Java) antes de qualquer operação com arquivo, e implemente verificações de TOCTOU (time-of-check-time-of-use). Mantenha operações sensíveis em diretórios controlados com permissões restritivas e evite processar symlinks vindos de áreas com controle de usuário.

CVE-2025-55245HIGHXbox Gaming Services Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2025-30371LOWMetabase vulnerable to circumvention of local link access protection in GeoJson endpointEPSS 0.4%CVE-2025-68279HIGHWeblate has an arbitrary file read via symbolic linksEPSS 0.4%CVE-2026-50135MEDIUMHugo: Symlink confinement bypass in resources.GetEPSS 0.4%CVE-2026-77815HIGHInfinite Image Browsing Resolves Paths With normpath, Allowing Symlink Escape From Scanned DirectoriesEPSS 0.4%CVE-2020-36657HIGHuptimed before 0.4.6-r1 on Gentoo allows local users (with access to the uptimed user account) to gain root privileges by creating a hard liEPSS 0.4%CVE-2019-3699HIGHLocal privilege escalation from user privoxy to rootEPSS 0.4%CVE-2026-42834HIGHWindows Admin Center in Azure Portal Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2026-34603HIGH@tinacms/graphql's Media Endpoints Can Escape the Media Root via Symlinks or JunctionsEPSS 0.4%CVE-2026-20310CRITICALCisco SD-WAN Software Security Hardening Release - Improper Link Resolution Before File AccessEPSS 0.4%CVE-2024-7238HIGHVIPRE Advanced Security SBAMSvc Link Following Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2025-48820HIGHWindows AppX Deployment Service Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-4454HIGHWithSecure Elements Endpoint Protection Link Following Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-41882HIGHIn JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible viEPSS 0.4%CVE-2023-27469Malwarebytes Anti-Exploit 4.4.0.220 is vulnerable to arbitrary file deletion and denial of service via an ALPC message in which FullFileNameEPSS 0.4%CVE-2025-29795HIGHMicrosoft Edge (Chromium-based) Update Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2024-3037HIGHArbitrary File Deletion in PaperCut NG/MF Web PrintEPSS 0.4%CVE-2024-1868HIGHG DATA Total Security Link Following Local Privilege Escalation VulnerabilityEPSS 0.4%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.4%CVE-2026-47277MEDIUMRuntipi: Unauthenticated arbitrary file read through app-store logo symlinksEPSS 0.4%