Falhas do tipo CWE-59

820 resultados

Seguimento de links simbólicos (symlink)

A aplicação segue links simbólicos sem validação, permitindo que um atacante redirecione operações de arquivo para locais não autorizados. Isso pode resultar em leitura, modificação ou exclusão de arquivos sensíveis fora do diretório esperado.

Exemplo

Um servidor web processa uploads em /tmp/uploads/, mas não verifica se os caminhos são links simbólicos. Um atacante cria um symlink em /tmp/uploads/config que aponta para /etc/passwd, e a aplicação sobrescreve o arquivo de senhas do sistema.

Como mitigar

Use funções que resolvem caminhos canônicos (realpath em C, Path.toRealPath() em Java) antes de qualquer operação com arquivo, e implemente verificações de TOCTOU (time-of-check-time-of-use). Mantenha operações sensíveis em diretórios controlados com permissões restritivas e evite processar symlinks vindos de áreas com controle de usuário.

CVE-2026-39243MEDIUMdecompress before 4.2.2 allows arbitrary hardlink creation during archive extraction, enabling file read disclosure and file corruption. WheEPSS 0.3%CVE-2025-34191HIGHVasion Print (formerly PrinterLogic) Arbitrary File Write as Root via Response Path Symlink FollowEPSS 0.3%CVE-2026-54706MEDIUMOnionShare follows symlinks in shared directories, allowing unintended disclosure of local filesEPSS 0.3%CVE-2021-32547HIGHapport read_file() function could follow maliciously constructed symbolic linksEPSS 0.3%CVE-2022-2897HIGHMeasuresoft ScadaPro Server and Client Link FollowingEPSS 0.3%CVE-2022-4563HIGHFreedom of the Press SecureDrop gpg-agent.conf symlinkEPSS 0.3%CVE-2025-43448MEDIUMThis issue was addressed with improved validation of symlinks. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1EPSS 0.3%CVE-2022-32905HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Ventura 13. Processing a maliciously crafted DMGEPSS 0.3%CVE-2022-2145MEDIUMCloudlfare WARP Arbitrary File OverwriteEPSS 0.3%CVE-2024-6260HIGHMalwarebytes Antimalware Link Following Local Privilege Escalation VulnerabilityEPSS 0.3%CVE-2025-69430MEDIUMAn Incorrect Symlink Follow vulnerability exists in multiple Yottamaster NAS devices, including DM2 (version equal to or prior to V1.9.12), EPSS 0.3%CVE-2025-69429MEDIUMThe ORICO NAS CD3510 (version V1.9.12 and below) contains an Incorrect Symlink Follow vulnerability that could be exploited by attackers to EPSS 0.3%CVE-2025-69431MEDIUMThe ZSPACE Q2C NAS contains a vulnerability related to incorrect symbolic link following. Attackers can format a USB drive to ext4, create aEPSS 0.3%CVE-2026-18267MEDIUMKenwood DNR1007XR Firmware Update Link Following Code Execution VulnerabilityEPSS 0.3%CVE-2026-62812HIGHWindows DHCP Server Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-38730MEDIUMDocker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by contEPSS 0.3%CVE-2026-47699MEDIUMConfidential Containers Guest Components image-rs: zip-slip-class arbitrary file write via absolute entry path in hardlink fallbackEPSS 0.3%CVE-2021-32549HIGHapport read_file() function could follow maliciously constructed symbolic linksEPSS 0.3%CVE-2026-48921HIGHJenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared libraries, allowing aEPSS 0.3%CVE-2021-32555HIGHapport read_file() function could follow maliciously constructed symbolic linksEPSS 0.3%