目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-180 不正确的行为次序:规范化之前验证 类漏洞列表 31

CWE-180 不正确的行为次序:规范化之前验证 类弱点 31 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-180属于输入验证顺序错误漏洞。攻击者通过构造特殊输入,利用系统在规范化前进行验证的缺陷,使数据在规范化后变为非法从而绕过检查,进而实施注入等攻击。开发者应遵循“先规范化,后验证”的原则,确保在统一数据格式后再执行合法性校验,以消除此类绕过风险,保障系统安全。

MITRE CWE 官方描述
CWE:CWE-180 错误的行为顺序:在规范化(Canonicalize)之前进行验证(Validate) 产品在输入被规范化(Canonicalize)之前对其进行验证(Validate),这导致产品无法检测到在规范化(Canonicalize)步骤之后变为无效的数据。 攻击者可以利用此问题绕过验证(Validate),并发起攻击以暴露原本会被防止的弱点,例如注入(Injection)。
常见影响 (1)
Access Control Bypass Protection Mechanism
缓解措施 (1)
Implementation Inputs should be decoded and canonicalized to the application's current internal representation before being validated (CWE-180). Make sure that the application does not decode the same input twice (CWE-174). Such errors could be used to bypass allowlist validation schemes by introducing dangerous inputs after they have been checked.
代码示例 (1)
The following code attempts to validate a given input path by checking it against an allowlist and then return the canonical path. In this specific case, the path is considered valid if it starts with the string "/safe_dir/".
String path = getInputPath(); if (path.startsWith("/safe_dir/")) { File f = new File(path); return f.getCanonicalPath(); }
Bad · Java
String path = getInputPath(); File f = new File(path); if (f.getCanonicalPath().startsWith("/safe_dir/")) { return f.getCanonicalPath(); }
Good · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2022-26136 Atlassian Crowd和Atlassian Jira 授权问题漏洞 — Bamboo Server 8.8 - 2022-07-20

CWE-180(不正确的行为次序:规范化之前验证) 是常见的弱点类别,本平台收录该类弱点关联的 31 条 CVE 漏洞。