Falhas do tipo CWE-942

134 resultados

Política de segurança cross-domain permissiva com domínios não confiáveis

Ocorre quando uma aplicação web configura mecanismos de controle de acesso cross-domain (CORS, postMessage, etc.) de forma muito aberta, permitindo que domínios não confiáveis ou controlados por atacantes acessem recursos sensíveis. Isso quebra o isolamento entre origens e expõe dados ou funcionalidades que deveriam ser protegidas.

Exemplo

Um servidor configurando Access-Control-Allow-Origin: * em endpoints que retornam dados de usuário, ou aceitando comunicação postMessage de qualquer origem sem validar o remetente. Um site malicioso pode então executar JavaScript que rouba tokens, credenciais ou informações privadas do usuário.

Como mitigar

Especifique explicitamente os domínios permitidos em CORS (nunca use wildcard em produção com dados sensíveis). Valide a origem nas requisições cross-domain e implemente verificações de token/sessão robustas. Para postMessage, sempre validate event.origin antes de processar a mensagem.

CVE-2023-46098HIGHA vulnerability has been identified in SIMATIC PCS neo (All versions < V4.1). When accessing the Information Server from affected products, EPSS 0.6%CVE-2021-34435In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the EPSS 0.6%CVE-2021-27786MEDIUMHCL OneTest Server is vulnerable to Cross Origin Resource Sharing: Arbitrary Origin TrustedEPSS 0.6%CVE-2024-53276MEDIUMGHSL-2024-092: Open CORS policy in home-galleryEPSS 0.5%CVE-2026-28792CRITICALCross-Origin File Exfiltration via CORS Misconfiguration + Path Traversal in TinaCMSEPSS 0.5%CVE-2024-49763HIGHPlexRipper allows API leak due to open CORS policyEPSS 0.5%CVE-2022-34366MEDIUM Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticatedEPSS 0.5%CVE-2026-34449CRITICALSiYuan: Cross-Origin RCE via Permissive CORS Policy and JavaScript Snippet InjectionEPSS 0.5%CVE-2024-37131HIGHSCG Policy Manager, all versions, contains an overly permissive Cross-Origin Resource Policy (CORP) vulnerability. A remote unauthenticated EPSS 0.5%CVE-2024-45642MEDIUMIBM Security ReaQta information disclosureEPSS 0.5%CVE-2023-23464HIGHMedia CP Media Control Panel – Information DisclosureEPSS 0.5%CVE-2025-43392MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in Safari 26.1, iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPaEPSS 0.5%CVE-2025-43480HIGHThe issue was addressed with improved checks. This issue is fixed in Safari 26.1, iOS 26.1 and iPadOS 26.1, macOS Tahoe 26.1, tvOS 26.1, visEPSS 0.5%CVE-2023-50940MEDIUMIBM PowerSC cross-resource origin sharingEPSS 0.5%CVE-2026-8919HIGHPermissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by coEPSS 0.4%CVE-2025-25264MEDIUMOverly Permissive CORS Policy in WAGO Device ManagerEPSS 0.4%CVE-2026-57957LOWPapermark 0.22.0 - CORS Misconfiguration in Viewer Upload EndpointEPSS 0.4%CVE-2023-37526MEDIUMHCL DRYiCE Lucy v9 (now AEX) is affected by a Cross Origin Resource Sharing (CORS) VulnerabilityEPSS 0.4%CVE-2024-32862MEDIUMexacqVision CORSEPSS 0.4%CVE-2026-89058HIGHResteasy-core: resteasy: corsfilter reflects arbitrary origin with credentials under wildcard configEPSS 0.4%