目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-359 侵犯隐私 类漏洞列表 147

CWE-359 侵犯隐私 类弱点 147 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-359 指软件未能有效防止未授权主体访问个人私密信息,属于隐私泄露类漏洞。攻击者常利用身份验证缺陷、权限配置错误或接口逻辑漏洞,非法获取敏感数据。开发者应实施严格的访问控制策略,确保仅授权用户可访问数据,同时遵循最小权限原则,并对敏感信息进行加密存储与传输,从而杜绝非授权访问风险。

MITRE CWE 官方描述
CWE:CWE-359 向未授权主体暴露私人个人信息 英文:产品未能有效防止某人的私人、个人信息被以下主体访问:(1) 未明确获得访问该信息授权的人员;或 (2) 未获得信息所涉人员默示同意的人员。
常见影响 (1)
Confidentiality Read Application Data
缓解措施 (3)
Requirements Identify and consult all relevant regulations for personal privacy. An organization may be required to comply with certain federal and state regulations, depending on its location, the type of business it conducts, and the nature of any private data it handles. Regulations may include Safe Harbor Privacy Framework [REF-340], Gramm-Leach Bliley Act (GLBA) [REF-341], Health Insurance Portability a…
Architecture and Design Carefully evaluate how secure design may interfere with privacy, and vice versa. Security and privacy concerns often seem to compete with each other. From a security perspective, all important operations should be recorded so that any anomalous activity can later be identified. However, when private data is involved, this practice can in fact create risk. Although there are many ways in which pri…
Implementation, Operation Some tools can automatically analyze documents to redact, strip, or "sanitize" private information, although some human review might be necessary. Tools may vary in terms of which document formats can be processed. When calling an external program to automatically generate or convert documents, invoke the program with any available options that avoid generating sensitive metada…
代码示例 (2)
The following code contains a logging statement that tracks the contents of records added to a database by storing them in a log file. Among other values that are stored, the getPassword() function returns the user-supplied plaintext password associated with the account.
pass = GetPassword(); ... dbmsLog.WriteLine(id + ":" + pass + ":" + type + ":" + tstamp);
Bad · C#
This code uses location to determine the user's current US State location.
<uses-permission android:name="android.permission.ACCESS_FINE_LOCATION"/>
Bad · XML
locationClient = new LocationClient(this, this, this); locationClient.connect(); Location userCurrLocation; userCurrLocation = locationClient.getLastLocation(); deriveStateFromCoords(userCurrLocation);
Bad · Java
CVE ID 标题 CVSS 风险等级 Published
CVE-2024-13953 ABB多款产品 安全漏洞 — ASPECT-Enterprise 4.9 Medium 2025-05-22
CVE-2025-0679 GitLab Enterprise Edition(EE)和GitLab Community Edition(CE) 安全漏洞 — GitLab 4.3 Medium 2025-05-22
CVE-2023-45721 HCL Leap 安全漏洞 — HCL Domino Leap 5.3 Medium 2025-04-30
CVE-2023-45720 HCL Leap 安全漏洞 — HCL Leap 5.3 Medium 2025-04-24
CVE-2024-42325 Zabbix 安全漏洞 — Zabbix 7.5AI High AI 2025-04-02
CVE-2024-10267 SuperAGI 安全漏洞 — transformeroptimus/superagi 7.5 - 2025-03-20
CVE-2024-13228 WordPress plugin Qubely 安全漏洞 — Qubely – Advanced Gutenberg Blocks 4.3 Medium 2025-03-11
CVE-2025-20060 Dario Health 安全漏洞 — USB-C Blood Glucose Monitoring System Starter Kit Android Applications 7.5 High 2025-02-28
CVE-2024-13217 WordPress plugin Jeg Elementor Kit 安全漏洞 — Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress 4.3 Medium 2025-02-27
CVE-2025-20615 Qardio ARM A100 安全漏洞 — Heart Health IOS Mobile Application 6.2 Medium 2025-02-13
CVE-2024-12041 WordPress plugin Directorist 安全漏洞 — Directorist: AI-Powered Business Directory, Listings & Classified Ads 5.3 Medium 2025-02-01
CVE-2024-13216 WordPress plugin HT Event – WordPress Event Manager Plugin for Elementor 安全漏洞 — HT Event – WordPress Event Manager Plugin for Elementor 4.3 Medium 2025-01-31
CVE-2025-0683 Contec Health CMS8000 Patient Monitor 安全漏洞 — CMS8000 Patient Monitor 5.9 Medium 2025-01-30
CVE-2025-24355 Updatecli 安全漏洞 — updatecli 6.5 - 2025-01-24
CVE-2024-13215 WordPress plugin Elementor Addon Elements 安全漏洞 — Addon Elements for Elementor (formerly Elementor Addon Elements) 4.3 Medium 2025-01-15
CVE-2024-11396 WordPress plugin Event Monster 安全漏洞 — Event Monster – Manager & Ticket Booking 5.3 Medium 2025-01-13
CVE-2024-41780 IBM Jazz Foundation 安全漏洞 — Jazz Foundation 4.2 Medium 2025-01-03
CVE-2024-49765 Discourse 安全漏洞 — discourse 5.3 Medium 2024-12-19
CVE-2024-11712 WordPress plugin WP Job Portal 安全漏洞 — WP Job Portal – AI-Powered Recruitment System for Company or Job Board website 5.3 Medium 2024-12-14
CVE-2024-42494 Ruijie Networks ReyeeOS 安全漏洞 — Reyee OS 6.5 Medium 2024-12-06
CVE-2024-53258 Autolab 安全漏洞 — Autolab 6.5AI Medium AI 2024-11-25
CVE-2024-49025 Microsoft Edge 安全漏洞 — Microsoft Edge (Chromium-based) 5.4 Medium 2024-11-14
CVE-2024-11206 Phoenix com.transsion.phoenix 安全漏洞 — com.transsion.phoenix 7.5 - 2024-11-14
CVE-2023-44255 Fortinet FortiManager 安全漏洞 — FortiManager 3.9 Medium 2024-11-12
CVE-2024-49386 Acronis Cyber Files 安全漏洞 — Acronis Cyber Files 6.5AI Medium AI 2024-10-17
CVE-2024-47087 Apex Softcell LD Geo 安全漏洞 — LD Geo 6.5AI Medium AI 2024-09-19
CVE-2024-47085 Apex Softcell LD DP Back Office 安全漏洞 — LD DP Back Office 6.5AI Medium AI 2024-09-19
CVE-2024-8891 CIRCUTOR Q-SMT 安全漏洞 — CIRCUTOR Q-SMT 5.3 Medium 2024-09-18
CVE-2024-45787 Reedos aiM-Star 安全漏洞 — Mutual Fund Distribution Product (aiM-Star) 6.5AI Medium AI 2024-09-11
CVE-2024-44113 SAP Business Warehouse 安全漏洞 — SAP Business Warehouse (BEx Analyzer) 4.3 Medium 2024-09-10

CWE-359(侵犯隐私) 是常见的弱点类别,本平台收录该类弱点关联的 147 条 CVE 漏洞。