Falhas do tipo CWE-669

76 resultados

Transferência incorreta de recursos entre contextos de segurança

Ocorre quando um recurso (arquivo, memória, conexão, credencial) é movido ou compartilhado entre contextos de segurança diferentes (ex: processo privilegiado para não-privilegiado, zona confiável para não-confiável) sem validação ou proteção adequada. O recurso fica acessível a quem não deveria, ou perde suas garantias de segurança na transição.

Exemplo

Um aplicativo web salva dados sensíveis do usuário em /tmp com permissões 0644 (legível por todos), e outro processo de menor privilégio consegue ler. Ou um serviço transmite um file descriptor aberto para um cliente não autenticado, que ganha acesso ao arquivo sem passar por controles de autorização.

Como mitigar

Valide e controle explicitamente cada transferência de recurso: revise quem pode acessar o quê após a transferência, use permissões restritivas (0600), criptografe dados sensíveis em trânsito, e aplique re-autenticação ou re-autorização quando recursos cruzam limites de segurança.

CVE-2025-56675LOWThe EKEN video doorbell T6 BT60PLUS_MAIN_V1.0_GC1084_20230531 periodically sends debug logs to the EKEN cloud servers with sensitive informaEPSS 0.2%CVE-2026-32772LOWtelnet in GNU inetutils through 2.7 allows servers to read arbitrary environment variables from clients via NEW_ENVIRON SEND USERVAR.EPSS 0.2%CVE-2023-32803HIGHThe ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certEPSS 0.2%CVE-2026-48831HIGHWine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some coEPSS 0.2%CVE-2026-86144MEDIUMIn xinclude in libxml2 before 2.15.4, xmlXIncludeProcess and xmlXIncludeProcessTree do not propagate parseFlags. This has security relevanceEPSS 0.2%CVE-2026-40228LOWIn systemd 259, systemd-journald can send ANSI escape sequences to the terminals of arbitrary users when a "logger -p emerg" command is execEPSS 0.2%CVE-2026-41030MEDIUMIn ONLYOFFICE DesktopEditors before 9.3.0, the update service allows attackers to perform actions on files with SYSTEM privileges.EPSS 0.2%CVE-2026-73281LOWIn ssh-agent in OpenSSH before 10.5, some operations can occur remotely but were intended to occur only locally, including operations that aEPSS 0.2%CVE-2025-45480LOWFloodlight 71fe8a7 allows disruption of host communication via link spoofing. A port is misclassified as a non-boundary.EPSS 0.2%CVE-2025-59453LOWClick Studios Passwordstate before 9.9 Build 9972 has a potential authentication bypass for Passwordstate emergency access. By using a craftEPSS 0.2%CVE-2026-40225MEDIUMIn udev in systemd before 260, local root execution can occur via malicious hardware devices and unsanitized kernel output.EPSS 0.1%CVE-2025-59378MEDIUMIn guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular EPSS 0.1%CVE-2025-54956LOWThe gh package before 1.5.0 for R delivers an HTTP response in a data structure that includes the Authorization header from the correspondinEPSS 0.1%CVE-2026-41525MEDIUMKDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandboEPSS 0.1%CVE-2026-38924LOWIn Oraios AI Serena before 1.0.0, the listen address of the MCP server in HTTP mode is 0.0.0.0. NOTE: the Supplier observed that 0.0.0.0 wasEPSS 0.1%CVE-2026-89162LOWIn PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes to an adversary, typically in a situation where the access available EPSS 0.1%