Falhas do tipo CWE-732

785 resultados

Permissões Inadequadas em Recurso Crítico de Segurança

A aplicação ou sistema configura permissões de arquivo, diretório ou recurso de forma muito permissiva, permitindo que usuários ou processos não autorizados leiam ou modifiquem dados sensíveis. Isso viola o princípio do menor privilégio e expõe informações confidenciais ou permite alterações não intencionadas em arquivos críticos.

Exemplo

Um serviço web armazena chaves privadas de criptografia em um arquivo com permissões 644 (legível por qualquer usuário do sistema), permitindo que outro processo comprometido ou usuário local roube as credenciais. Ou um arquivo de configuração com senhas é gravado com permissões 777, permitindo modificação por qualquer usuário.

Como mitigar

Implemente permissões restritivas desde o início (ex: 600 para chaves privadas, 640 para configs sensíveis). Realize auditorias regulares de permissões em recursos críticos e use listas de controle de acesso (ACLs) para ser explícito sobre quem pode ler ou modificar cada recurso. Automatize verificações de permissões na pipeline CI/CD.

CVE-2025-21580MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.41, EPSS 0.7%CVE-2025-21579MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.0-8.0.EPSS 0.7%CVE-2023-0225MEDIUMA flaw was found in Samba. An incomplete access check on dnsHostName allows authenticated but otherwise unprivileged users to delete this atEPSS 0.7%CVE-2022-40756HIGHIf folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01EPSS 0.7%CVE-2023-35168MEDIUMDataEase has a privilege bypass vulnerabilityEPSS 0.7%CVE-2022-4365MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 11.8 before 15.5.7, all versions starting from 15.6 beforeEPSS 0.7%CVE-2024-37087MEDIUMThe vCenter Server contains a denial-of-service vulnerability. A malicious actor with network access to vCenter Server may create a denial-oEPSS 0.7%CVE-2022-43946HIGHMultiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check timeEPSS 0.7%CVE-2024-41647CRITICALInsecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitEPSS 0.7%CVE-2025-21566MEDIUMVulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 9.1.0 anEPSS 0.7%CVE-2022-40298HIGHCrestron AirMedia for Windows before 5.5.1.84 has insecure inherited permissions, which leads to a privilege escalation vulnerability found EPSS 0.7%CVE-2022-46338MEDIUMg810-led 0.4.2, a LED configuration tool for Logitech Gx10 keyboards, contained a udev rule to make supported device nodes world-readable anEPSS 0.7%CVE-2023-22294HIGHPrivilege escalation in Checkmk ApplianceEPSS 0.7%CVE-2022-36103HIGHTalos worker join token can be used to get elevated access level to the Talos APIEPSS 0.7%CVE-2024-44729HIGHIncorrect access control in the component app/src/server.js of Mirotalk before commit 9de226 allows unauthenticated attackers without presenEPSS 0.7%CVE-2024-12564MEDIUMExposure of Sensitive Information to an Unauthorized Actor vulnerability in ODA CDE inWEB SDK before 2025.3EPSS 0.7%CVE-2025-30708HIGHVulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Search and Register Users). Supported versions tEPSS 0.7%CVE-2025-34212HIGHVasion Print (formerly PrinterLogic) Insecure Build PipelineEPSS 0.7%CVE-2024-24117CRITICALInsecure Permissions vulnerability in Ruijie RG-NBS2009G-P RGOS v.10.4(1)P2 Release (9736) allows a remote attacker to gain privileges via tEPSS 0.7%CVE-2026-10591HIGHKiro IDE Insufficient File Write Restrictions to Execution-Sensitive PathsEPSS 0.7%