Falhas do tipo CWE-693

836 resultados

Falha em Mecanismo de Proteção

CWE-693 descreve quando um mecanismo de segurança implementado no software não funciona como deveria, seja por design deficiente, implementação incorreta ou bypass não intencional. O resultado é que uma ou mais camadas de defesa falham, deixando o sistema exposto a ataques que deveriam ter sido bloqueados.

Exemplo

Um sistema implementa validação de entrada apenas no cliente (JavaScript), mas deixa a API backend sem validação equivalente. Um atacante contorna a proteção do cliente e envia dados maliciosos diretamente para o servidor, que as aceita sem filtro. O mecanismo de proteção falhou porque estava incompleto.

Como mitigar

Implementar controles de segurança em profundidade (nunca confiar apenas em uma camada), validar e sanitizar dados em todos os pontos de entrada, testar regularmente se as proteções estão funcionando conforme esperado, e documentar claramente qual é a intenção de cada controle de segurança.

CVE-2024-5691MEDIUMBy tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would EPSS 0.7%CVE-2025-59326CRITICALCPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for uEPSS 0.6%CVE-2025-43273CRITICALA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.8. A sandEPSS 0.6%CVE-2024-43513MEDIUMBitLocker Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2024-6741MEDIUMOpenfind Mail2000 - HttpOnly flag bypassEPSS 0.6%CVE-2022-27516MEDIUMUser login brute force protection functionality bypass EPSS 0.6%CVE-2025-71352HIGHpicklescan - Remote Code Execution via Undetected trace.Trace.runctx in Pickle FilesEPSS 0.6%CVE-2026-66391MEDIUMApache Wicket: leaked and missing CSP headersEPSS 0.6%CVE-2025-71373HIGHpicklescan - Remote Code Execution via operator.methodcaller Detection BypassEPSS 0.6%CVE-2024-26250MEDIUMSecure Boot Security Feature Bypass VulnerabilityEPSS 0.6%CVE-2026-92124HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier checks the operations Groovy will perform with the elements it reads from aEPSS 0.6%CVE-2026-92123HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not intercept operations performed on a null receiver (method calls, pEPSS 0.6%CVE-2026-92122HIGHJenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not check the method called through the proxy created when a sandboxedEPSS 0.6%CVE-2026-76825HIGHRestrictedPython: Sandbox escape via string.Formatter field resolutionEPSS 0.6%CVE-2026-39420MEDIUMMaxKB: Sandbox escape via LD_PRELOAD bypassEPSS 0.6%CVE-2024-28248HIGHCilium intermittent HTTP policy bypassEPSS 0.6%CVE-2024-33883MEDIUMThe ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.EPSS 0.6%CVE-2025-41232CRITICALCVE-2025-41232: Spring Security authorization bypass for method security annotations on private methodsEPSS 0.6%CVE-2026-6876CRITICALSandbox Escape in ServiceNow AI PlatformEPSS 0.6%CVE-2026-46634HIGHTwig: `template_from_string()` escapes a SourcePolicy-driven sandbox via synthesized template nameEPSS 0.6%