Weaknesses of type CWE-277

71 results

Permissões Herdadas Inseguras

Ocorre quando um processo, arquivo, diretório ou recurso herda permissões de acesso de seu pai de forma insegura, permitindo que usuários sem privilégio adequado acessem ou modifiquem dados sensíveis. O problema é que a aplicação não valida ou restringe essas permissões após a herança, deixando brechas na cadeia de controle de acesso.

Example

Um arquivo temporário criado dentro de um diretório com permissões amplas (777) herda automaticamente essa abertura. Se a aplicação não redefine as permissões do arquivo para algo mais restritivo (por exemplo, 600), qualquer usuário do sistema consegue ler ou alterar dados sensíveis ali armazenados, como tokens ou credenciais.

How to mitigate

Sempre defina explicitamente permissões restritivas no momento da criação de arquivos, diretórios e processos, sem depender da herança do pai. Use umask apropriado, aplique ACLs explícitas e valide permissões em tempo de execução, especialmente para recursos que lidam com dados sensíveis.

CVE-2023-39230MEDIUMInsecure inherited permissions in some Intel Rapid Storage Technology software before version 16.8.5.1014.9 may allow an authenticated user EPSS 0.2%CVE-2023-33870MEDIUMInsecure inherited permissions in some Intel(R) Ethernet tools and driver install software may allow an authenticated user to potentially enEPSS 0.2%CVE-2022-33898MEDIUMInsecure inherited permissions in some Intel(R) NUC Watchdog Timer installation software before version 2.0.21.0 may allow an authenticated EPSS 0.2%CVE-2022-41700MEDIUMInsecure inherited permissions in some Intel(R) NUC Pro Software Suite installation software before version 2.0.0.9 may allow an authenticatEPSS 0.2%CVE-2025-20008MEDIUMInsecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potEPSS 0.2%CVE-2023-33990HIGHDenial of Service (DoS) vulnerability in SAP SQL AnywhereEPSS 0.2%CVE-2023-28207MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.3, macOS Monterey 12.6.4, macOS Big Sur 11.7.5. A plugEPSS 0.2%CVE-2024-21835MEDIUMInsecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable EPSS 0.2%CVE-2022-38103MEDIUMInsecure inherited permissions in the Intel(R) NUC Software Studio Service installer before version 1.17.38.0 may allow an authenticated useEPSS 0.1%CVE-2022-41687MEDIUMInsecure inherited permissions in the HotKey Services for some Intel(R) NUC P14E Laptop Element software for Windows 10 before version 1.1.4EPSS 0.1%CVE-2024-51448MEDIUMIBM Robotic Process Automation privilege escalationEPSS 0.1%CVE-2022-46656MEDIUMInsecure inherited permissions for the Intel(R) NUC Pro Software Suite before version 2.0.0.3 may allow an authenticated user to potentiallyEPSS 0.1%CVE-2022-41658MEDIUMInsecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentiaEPSS 0.1%CVE-2025-31332MEDIUMInsecure File permissions vulnerability in SAP BusinessObjects Business Intelligence PlatformEPSS 0.1%CVE-2025-32797MEDIUMConda-build Insecure Build Script Permissions Enabling Arbitrary Code ExecutionEPSS 0.1%CVE-2024-36294MEDIUMInsecure inherited permissions for some Intel(R) DSA software before version 24.3.26.8 may allow an authenticated user to potentially enableEPSS 0.1%CVE-2024-36276MEDIUMInsecure inherited permissions for some Intel(R) CIP software before version 2.4.10852 may allow an authenticated user to potentially enableEPSS 0.1%CVE-2022-36377MEDIUMInsecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before versioEPSS 0.1%CVE-2025-29982MEDIUMDell Wyse Management Suite, versions prior to WMS 5.1, contains an Insecure Inherited Permissions vulnerability. A low privileged attacker wEPSS 0.1%CVE-2023-34391HIGHInsecure Inherited PermissionsEPSS 0.1%