Falhas do tipo CWE-732

790 resultados

Permissões Inadequadas em Recurso Crítico de Segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso viola o princípio do menor privilégio e expõe informações confidenciais ou permite alterações não intencionadas em arquivos críticos.

Exemplo

Um serviço web armazena chaves privadas de criptografia em um arquivo com permissões 644 (legível por qualquer usuário do sistema), permitindo que outro processo comprometido ou usuário local roube as credenciais. Ou um arquivo de configuração com senhas é gravado com permissões 777, permitindo modificação por qualquer usuário.

Como mitigar

Implemente permissões restritivas desde o início (ex: 600 para chaves privadas, 640 para configs sensíveis). Realize auditorias regulares de permissões em recursos críticos e use listas de controle de acesso (ACLs) para ser explícito sobre quem pode ler ou modificar cada recurso. Automatize verificações de permissões na pipeline CI/CD.

CVE-2024-2905MEDIUMRpm-ostree: world-readable /etc/shadow fileEPSS 0.3%CVE-2019-19335MEDIUMDuring installation of an OpenShift 4 cluster, the `openshift-install` command line tool creates an `auth` directory, with `kubeconfig` and EPSS 0.3%CVE-2022-32929MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in iOS 15.7.1 and iPadOS 15.7.1, iOS 15.7 and iPadOS 15.EPSS 0.3%CVE-2025-34323HIGHNagios Log Server < 2026R1.0.1 Local Privilege Escalation via Writable Scripts and Sudo RulesEPSS 0.3%CVE-2023-49797HIGHLocal Privilege Escalation in pyinstaller on WindowsEPSS 0.3%CVE-2023-31142LOWDiscourse's general category permissions could be set back to defaultEPSS 0.3%CVE-2023-49257HIGHCommand execution using the certificate upload utilityEPSS 0.3%CVE-2025-12004CRITICALThe compare API module breaks Extension:LockdownEPSS 0.3%CVE-2024-45164MEDIUMAkamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch anEPSS 0.3%CVE-2024-39967MEDIUMInsecure permissions in Aginode GigaSwitch v5 allows attackers to access sensitive information via using the SCP command.EPSS 0.3%CVE-2019-19341MEDIUMA flaw was found in Ansible Tower, versions 3.6.x before 3.6.2, where files in '/var/backup/tower' are left world-readable. These files inclEPSS 0.3%CVE-2025-52873HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2025-54497HIGHCognex In-Sight Explorer and In-Sight Camera Firmware Incorrect Permission Assignment for Critical ResourceEPSS 0.3%CVE-2020-10781MEDIUMA flaw was found in the Linux Kernel before 5.8-rc6 in the ZRAM kernel module, where a user with a local account and the ability to read theEPSS 0.3%CVE-2019-5642LOWMAGICKEPSS 0.3%CVE-2025-0093HIGHIn handleBondStateChanged of AdapterService.java, there is a possible unapproved data access due to a missing permission check. This could lEPSS 0.3%CVE-2024-41954MEDIUMFOG Weak file permissionsEPSS 0.3%CVE-2016-8637MEDIUMA local information disclosure issue was found in dracut before 045 when generating initramfs images with world-readable permissions when 'eEPSS 0.3%CVE-2024-6360MEDIUMIncorrect Permission Assignment for Critical Resource vulnerability has been discovered in OpenText™ Vertica.EPSS 0.3%CVE-2023-3322HIGH Code Execution through overwriting service executable in utilities directoryEPSS 0.3%