Falhas do tipo CWE-732

785 resultados

Permissões Inadequadas em Recurso Crítico de Segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso viola o princípio do menor privilégio e expõe informações confidenciais ou permite alterações não intencionadas em arquivos críticos.

Exemplo

Um serviço web armazena chaves privadas de criptografia em um arquivo com permissões 644 (legível por qualquer usuário do sistema), permitindo que outro processo comprometido ou usuário local roube as credenciais. Ou um arquivo de configuração com senhas é gravado com permissões 777, permitindo modificação por qualquer usuário.

Como mitigar

Implemente permissões restritivas desde o início (ex: 600 para chaves privadas, 640 para configs sensíveis). Realize auditorias regulares de permissões em recursos críticos e use listas de controle de acesso (ACLs) para ser explícito sobre quem pode ler ou modificar cada recurso. Automatize verificações de permissões na pipeline CI/CD.

CVE-2025-1731HIGHAn incorrect permission assignment vulnerability in the PostgreSQL commands of the Zyxel USG FLEX H series uOS firmware versions from V1.20 EPSS 0.9%CVE-2021-32526MEDIUMQSAN Storage Manager - Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2019-3683HIGHkeystone_json_assignment backend granted access to any project for users in user-project-map.jsonEPSS 0.9%CVE-2021-40331HIGHPermissions problem in the Apache Ranger Hive PluginEPSS 0.9%CVE-2021-38475HIGHAUVESY VersiondogEPSS 0.9%CVE-2021-22648HIGHOvarro TBox Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2021-35248MEDIUMUnrestricted access to Orion.UserSettings SWIS entity for low-privilege usersEPSS 0.9%CVE-2023-28346HIGHAn issue was discovered in Faronics Insight 10.0.19045 on Windows. It is possible for a remote attacker to communicate with the private API EPSS 0.9%CVE-2022-48257MEDIUMIn Eternal Terminal 6.2.1, etserver and etclient have predictable logfile names in /tmp.EPSS 0.9%CVE-2023-0757CRITICALPhoenix Contact ProConOS prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2023-46141CRITICALPhoenix Contact: Automation Worx and classic line controllers prone to Incorrect Permission Assignment for Critical ResourceEPSS 0.9%CVE-2017-8450X-Pack 5.1.1 did not properly apply document and field level security to multi-search and multi-get requests so users without access to a doEPSS 0.9%CVE-2025-21581MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-21584MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.9%CVE-2025-30685MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-30683MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2025-21585MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.EPSS 0.9%CVE-2025-30684MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.0-EPSS 0.9%CVE-2022-35250MEDIUMA privilege escalation vulnerability exists in Rocket.chat <v5 which made it possible to elevate privileges for any authenticated user to viEPSS 0.9%CVE-2025-21583MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.4.0 and 9.0EPSS 0.8%