Fallos del tipo CWE-358

114 resultados

Verificação de segurança incompleta ou inadequada para padrão

A aplicação implementa um controle ou validação de segurança, mas de forma insuficiente ou que não cobre todos os casos necessários conforme o padrão esperado. Isso deixa brechas por onde um atacante consegue contornar a proteção ou explorar cenários não previstos na validação.

Ejemplo

Um sistema valida se um arquivo tem extensão .pdf antes de aceitar upload, mas não verifica o conteúdo real do arquivo — atacante envia um executável renomeado para .pdf e consegue executá-lo. Ou um serviço autentica por IP do cliente, mas não valida o token de sessão, deixando a porta aberta para roubo de sessão.

Cómo mitigar

Implemente validações em profundidade (validar não só formato, mas conteúdo, contexto e intenção), siga padrões consolidados de segurança da sua stack (OWASP, RFC de autenticação, etc) e realize testes de contorno — tenha alguém tentando quebrar cada verificação. Code review focado em completude de controles também é crítico.

CVE-2021-34791MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass VulnerabilitiesEPSS 1.1%CVE-2021-34790MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software Application Level Gateway Bypass VulnerabilitiesEPSS 1.1%CVE-2023-28601HIGHZoom for Windows clients prior to 5.14.0 contain an improper restriction of operations within the bounds of a memory buffer vulnerability. EPSS 1.0%CVE-2019-14823MEDIUMA flaw was found in the "Leaf and Chain" OCSP policy implementation in JSS' CryptoManager versions after 4.4.6, 4.5.3, 4.6.0, where it impliEPSS 0.9%CVE-2026-44513HIGHDiffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom componentsEPSS 0.8%CVE-2023-3266CRITICALA non-feature complete authentication mechanism exists in the production application allowing an attacker to bypass all authentication checkEPSS 0.8%CVE-2024-6101HIGHInappropriate implementation in V8 in Google Chrome prior to 126.0.6478.114 allowed a remote attacker to perform out of bounds memory accessEPSS 0.8%CVE-2021-31375HIGHJunos OS: Receipt of a specific BGP update may cause RPKI policy-checks to be bypassedEPSS 0.8%CVE-2020-1728MEDIUMA vulnerability was found in all versions of Keycloak where, the pages on the Admin Console area of the application are completely missing gEPSS 0.8%CVE-2024-3845CRITICALInappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy viEPSS 0.8%CVE-2020-10743It was discovered that OpenShift Container Platform's (OCP) distribution of Kibana could open in an iframe, which made it possible to intercEPSS 0.7%CVE-2023-40445HIGHThe issue was addressed with improved UI handling. This issue is fixed in iOS 17.1 and iPadOS 17.1. A device may persistently fail to lock.EPSS 0.7%CVE-2023-2585LOWKeycloak: client access via device auth request spoofEPSS 0.7%CVE-2026-50628CRITICALApache CXF: OAuth2: Inverted IP Binding Check Defeats Security ControlEPSS 0.7%CVE-2024-2617HIGHA vulnerability exists in the RTU500 that allows for authenticated and authorized users to bypass secure update, if secure update feature EPSS 0.7%CVE-2024-3844MEDIUMInappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crEPSS 0.6%CVE-2022-38732HIGHSnapCenter versions prior to 4.7 shipped without Content Security Policy (CSP) implemented which could allow certain types of attacks that oEPSS 0.6%CVE-2020-1761A flaw was found in the OpenShift web console, where the access token is stored in the browser's local storage. An attacker can use this flaEPSS 0.6%CVE-2022-27219A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP EPSS 0.6%CVE-2022-27220A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.0 SP2). Affected application is missing general HTTP EPSS 0.6%