Falhas do tipo CWE-639

2.437 resultados

Manipulação de identificadores para contornar controle de acesso

A aplicação não valida adequadamente se o usuário autenticado tem permissão para acessar o recurso identificado pelo parâmetro fornecido (ID de registro, número de documento, etc.). Um atacante modifica esse parâmetro para acessar dados de outros usuários — por exemplo, mudando `user_id=123` para `user_id=124` na URL e obtendo informações alheias sem autenticação adicional.

Exemplo

Um banco permite visualizar extrato em `/api/extrato?conta=1001`. Um cliente autenticado como `user_123` descobre que pode acessar `/api/extrato?conta=1002` e ver o extrato completo de outra pessoa, porque o servidor apenas verifica se há uma sessão válida, não se aquele usuário é dono da conta 1002.

Como mitigar

Implemente validação de propriedade em cada requisição: antes de retornar dados, confirme que o ID do recurso pertence ao usuário autenticado. Use referências indiretas (tokens opacos) em vez de IDs sequenciais previsíveis, e aplique testes automatizados que tentam acessar recursos de outros usuários.

CVE-2021-24562LifterLMS < 4.21.2 - Access Other Student Grades/Answers via IDOREPSS 1.6%CVE-2021-41306HIGHAffected versions of Atlassian Jira Server and Data Center allow anonymous remote attackers to view private project and filter names via an EPSS 1.6%CVE-2024-46528MEDIUMAn Insecure Direct Object Reference (IDOR) vulnerability in KubeSphere 4.x before 4.1.3 and 3.x through 3.4.1 and KubeSphere Enterprise 4.x EPSS 1.6%CVE-2022-1580Site Offline < 1.5.3 - Access BypassEPSS 1.6%CVE-2022-3805HIGHJeg Elementor Kit <= 2.5.6 - Unauthenticated Authorization BypassEPSS 1.6%CVE-2022-0613MEDIUMAuthorization Bypass Through User-Controlled Key in medialize/uri.jsEPSS 1.6%CVE-2026-8679HIGHAudioIgniter Music Player <= 2.0.2 - Unauthenticated Insecure Direct Object Reference to 'audioigniter_playlist_id' ParameterEPSS 1.6%CVE-2024-10654MEDIUMTOTOLINK LR350 formLoginAuth.htm authorizationEPSS 1.6%CVE-2022-0639MEDIUMAuthorization Bypass Through User-Controlled Key in unshiftio/url-parseEPSS 1.5%CVE-2021-24374Jetpack < 9.8 - Carousel Module Non-Published Page/Post Attachment Comment LeakEPSS 1.5%CVE-2021-36387MEDIUMIn Yellowfin before 9.6.1 there is a Stored Cross-Site Scripting vulnerability in the video embed functionality exploitable through a speciaEPSS 1.5%CVE-2024-7476MEDIUMBroken Access Control in lunary-ai/lunaryEPSS 1.5%CVE-2021-21324MEDIUMInsecure Direct Object Reference (IDOR) on "Solutions"EPSS 1.4%CVE-2020-13998HIGHCitrix XenApp 6.5, when 2FA is enabled, allows a remote unauthenticated attacker to ascertain whether a user exists on the server, because tEPSS 1.4%CVE-2024-50395MEDIUMMedia Streaming add-onEPSS 1.4%CVE-2020-8297Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user iEPSS 1.3%CVE-2021-39225HIGHMissing permission check on Deck APIEPSS 1.3%CVE-2017-0922Gitlab Enterprise Edition version 10.3 is vulnerable to an authorization bypass issue in the GitLab Projects::BoardsController component resEPSS 1.3%CVE-2023-3048CRITICALIDOR in TMT's LockcellEPSS 1.3%CVE-2021-43957HIGHAffected versions of Atlassian Fisheye & Crucible allowed remote attackers to browse local files via an Insecure Direct Object References (IEPSS 1.3%