目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-347 密码学签名的验证不恰当 类漏洞列表 560

CWE-347 密码学签名的验证不恰当 类弱点 560 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-347 属于完整性校验缺失类漏洞,指软件未正确验证数据的加密签名。攻击者常通过篡改数据并伪造签名,实施中间人攻击或注入恶意载荷,从而绕过身份认证或数据完整性检查。开发者应确保对所有关键数据使用强加密算法进行签名验证,严格校验签名有效性,并在验证失败时拒绝处理,以保障数据真实性和系统安全。

MITRE CWE 官方描述
CWE:CWE-347 加密签名验证不当 英文:产品未验证或错误验证数据的加密签名(cryptographic signature)。
常见影响 (1)
Access Control, Integrity, Confidentiality Gain Privileges or Assume Identity, Modify Application Data, Execute Unauthorized Code or Commands
An attacker could gain access to sensitive data and possibly execute unauthorized code.
代码示例 (1)
In the following code, a JarFile object is created from a downloaded file.
File f = new File(downloadedFilePath); JarFile jf = new JarFile(f);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-102268 PyJWT非对称PEM检测绕过漏洞 — pyjwt 9.1 Critical 2026-09-28
CVE-2026-102266 PyJWK HMAC密钥空值绕过漏洞 — pyjwt 7.4 High 2026-09-28
CVE-2026-94418 WOLFSSL 小证书验证下日期错误掩盖签名失败漏洞 — wolfSSL 2.3 Low 2026-09-27
CVE-2025-71422 Contrast 1.12.1 LUKS2持久存储漏洞 — contrast 5.7 Medium 2026-09-27
CVE-2026-61855 Zammad 入站邮件无效 PGP 签名误报漏洞 — zammad 5.3 Medium 2026-09-25
CVE-2026-97732 Ironshield 1.0.0.167内核驱动绕过认证漏洞 — Ironshield 5.1 Medium 2026-09-25
CVE-2026-97731 MinIO<7aac2a2越权复制漏洞 — MinIO 7.1 High 2026-09-25
CVE-2026-91187 Nimble ZTA Cloudflare策略加密签名验证漏洞 — nimble_zta 9.3 Critical 2026-09-24
CVE-2026-91814 Foxit PDF 编辑器/阅读器签名验证绕过 — Foxit PDF Editor 5.3 Medium 2026-09-23
CVE-2026-18152 IBM Financial Transaction Manager 多重漏洞 — Financial Transaction Manager (FTM) for RedHat OpenShift 7.4 High 2026-09-22
CVE-2026-85995 Notepad++ Authenticode验证绕过执行漏洞 — notepad-plus-plus 7.3 High 2026-09-22
CVE-2026-95503 Keycloak Kerberos身份验证KDC欺骗绕过漏洞 — Red Hat Build of Keycloak 6.8 Medium 2026-09-22
CVE-2026-75939 OpenShift/oc-mirror 签名验证逻辑漏洞 — Red Hat OpenShift Container Platform 4 7.4 High 2026-09-21
CVE-2026-94368 Noobaa-core预签名URL越权复制对象漏洞 — Red Hat Openshift Data Foundation 4 7.1 High 2026-09-21
CVE-2026-9832 Stripe for WooCommerce 5.0.8 签名验证漏洞 — Payment Gateway of Stripe for WooCommerce 5.3 Medium 2026-09-19
CVE-2026-59163 Mnemosyne 服务器 JWT签名验证绕过漏洞 — mnemosyne 9.1 Critical 2026-09-18
CVE-2026-93657 hickory-resolver 0.26.2前 DNSSEC验证绕过漏洞 — hickory-resolver 7.5 High 2026-09-18
CVE-2026-28199 NetBackup Flex OS Shell 相对路径敏感文件泄露漏洞 — NetBackup Flex OS 3.3 Low 2026-09-18
CVE-2026-28198 NetBackup Flex OS Shell 签名验证绕过提权漏洞 — NetBackup Flex OS 8.8 High 2026-09-18
CVE-2026-78223 AshAuthentication 凭据撤销记录 JWT 验证漏洞 — ash_authentication 6.9 Medium 2026-09-17
CVE-2026-92718 Nuclei 3.11.1前模板签名绕过漏洞 — nuclei 7.3 High 2026-09-16
CVE-2026-42784 Sequoia-openpgp 密钥标志混淆致密码完整性漏洞 — Red Hat Ansible Automation Platform 2.6 for RHEL 9 7.4 High 2026-09-16
CVE-2026-86585 固件签名验证不当漏洞 — DUOX PLUS monitor firmware (VEO Wi-Fi range) 7.7 High 2026-09-16
CVE-2026-86109 安全公告0182 — VeloCloud Edge 6.6 Medium 2026-09-16
CVE-2026-58200 Cloudinary插件 API参数签名漏洞 — payload-plugins 7.1 High 2026-09-15
CVE-2026-54155 node-opcua 加密问题漏洞 — node-opcua 7.7 High 2026-09-14
CVE-2026-87802 Apache Syncope 加密问题漏洞 — Apache Syncope - - 2026-09-14
CVE-2026-54248 Kim Oliver Drechsel doco-cd 加密问题漏洞 — doco-cd 6.5 Medium 2026-09-11
CVE-2026-80469 SICK AG Sentio Creator Extension 'Device Manager' 加密问题漏洞 — Sentio Creator Extension 'Device Manager' 8.3 High 2026-09-11
CVE-2026-73784 Hewlett Packard Enterprise HPE IceWall products 加密问题漏洞 — HPE IceWall products 8.8 High 2026-09-11

CWE-347(密码学签名的验证不恰当) 是常见的弱点类别,本平台收录该类弱点关联的 560 条 CVE 漏洞。