CWE-36 绝对路径遍历 类弱点 111 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-36绝对路径遍历属于文件访问控制漏洞。当软件利用外部输入构建受限目录内的文件路径时,若未正确过滤绝对路径序列(如“/abs/path”),攻击者即可绕过限制,访问受限目录外的敏感文件或系统资源。开发者应严格验证输入,禁止使用绝对路径,并采用白名单机制或规范化路径处理,确保最终解析路径始终位于预期的安全沙箱内。
String filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);import os import sys def main(): filename = sys.argv[1] path = os.path.join(os.getcwd(), filename) try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()import os import sys def main(): filename = sys.argv[1] path = os.path.normpath(f"{os.getcwd()}{os.sep}{filename}") if path.startswith("/home/cwe/documents/"): try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-13160 | Ivanti EPM 安全漏洞 — Endpoint Manager | 9.8 | Critical | 2025-01-14 |
| CVE-2024-13161 | Ivanti EPM 安全漏洞 — Endpoint Manager | 9.8 | Critical | 2025-01-14 |
| CVE-2024-10811 | Ivanti EPM 安全漏洞 — Endpoint Manager | 9.8 | Critical | 2025-01-14 |
| CVE-2024-51549 | ABB ASPECT 安全漏洞 — ASPECT-Enterprise | 10.0 | Critical | 2024-12-05 |
| CVE-2024-11978 | Interinfo DreamMaker 安全漏洞 — DreamMaker | 7.5 | High | 2024-11-29 |
| CVE-2024-10651 | CHANGING IDExpert 安全漏洞 — IDExpert | 4.9 | Medium | 2024-11-01 |
| CVE-2024-47883 | Butterfly 安全漏洞 — simile-butterfly | 9.1 | Critical | 2024-10-24 |
| CVE-2024-20379 | Cisco Secure Firewall Management Center 安全漏洞 — Cisco Firepower Management Center | 6.5 | Medium | 2024-10-23 |
| CVE-2024-9924 | Hgiga OAKlouds 安全漏洞 — OAKlouds | 9.8 | Critical | 2024-10-14 |
| CVE-2024-45290 | PhpSpreadsheet 安全漏洞 — PhpSpreadsheet | 7.7 | High | 2024-10-07 |
| CVE-2024-45291 | PhpSpreadsheet 安全漏洞 — PhpSpreadsheet | 6.3 | Medium | 2024-10-07 |
| CVE-2024-8497 | Franklin Fueling TS-550 EVO Automatic Tank Gauge 安全漏洞 — TS-550 EVO | 7.5 | High | 2024-09-24 |
| CVE-2024-8778 | SYSCOM OMFLOW 安全漏洞 — OMFLOW | 6.5 | Medium | 2024-09-16 |
| CVE-2024-7323 | DigiWin EasyFlow .NET 安全漏洞 — EasyFlow .NET | 6.5 | Medium | 2024-08-02 |
| CVE-2024-20401 | Cisco Secure Email 安全漏洞 — Cisco Secure Email | 9.8 | Critical | 2024-07-17 |
| CVE-2024-6250 | LoLLMs 安全漏洞 — parisneo/lollms-webui | 7.5AI | HighAI | 2024-06-27 |
| CVE-2024-4881 | LoLLMs 安全漏洞 — parisneo/lollms | 9.1AI | CriticalAI | 2024-06-06 |
| CVE-2024-2362 | LoLLMs 安全漏洞 — parisneo/lollms-webui | 9.1AI | CriticalAI | 2024-06-06 |
| CVE-2024-2548 | LoLLMs 安全漏洞 — parisneo/lollms-webui | 6.2AI | MediumAI | 2024-06-06 |
| CVE-2023-41830 | Motorola Ready For 安全漏洞 — Phones | 6.5 | Medium | 2024-05-03 |
| CVE-2024-29053 | Microsoft Defender 安全漏洞 — Microsoft Defender for IoT | 8.8 | High | 2024-04-09 |
| CVE-2024-21323 | Microsoft Defender 安全漏洞 — Microsoft Defender for IoT | 8.8 | High | 2024-04-09 |
| CVE-2024-1703 | CRMEB 安全漏洞 — CRMEB | 3.5 | Low | 2024-02-21 |
| CVE-2023-50955 | IBM InfoSphere Information Server 安全漏洞 — InfoSphere Information Server | 2.4 | Low | 2024-02-21 |
| CVE-2023-5390 | Honeywell Experion ControlEdge VirtualUOC和ControlEdge UOC 安全漏洞 — ControlEdge UOC | 5.3 | Medium | 2024-01-31 |
| CVE-2023-30970 | Palantir Gotham 安全漏洞 — com.palantir.gotham:blackbird-witchcraft | 6.5 | Medium | 2024-01-29 |
| CVE-2023-5115 | ansible 安全漏洞 — Red Hat Ansible Automation Platform 2.3 for RHEL 8 | 6.3 | Medium | 2023-12-18 |
| CVE-2023-36786 | Microsoft Skype for Business 安全漏洞 — Skype for Business Server 2015 CU13 | 7.2 | High | 2023-10-10 |
| CVE-2023-5022 | Desdev DedeCMS 安全漏洞 — DedeCMS | 5.5 | Medium | 2023-09-17 |
| CVE-2023-40597 | Splunk 路径遍历漏洞 — Splunk Enterprise | 7.8 | High | 2023-08-30 |
CWE-36(绝对路径遍历) 是常见的弱点类别,本平台收录该类弱点关联的 111 条 CVE 漏洞。