CWE-36 绝对路径遍历 类弱点 111 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-36绝对路径遍历属于文件访问控制漏洞。当软件利用外部输入构建受限目录内的文件路径时,若未正确过滤绝对路径序列(如“/abs/path”),攻击者即可绕过限制,访问受限目录外的敏感文件或系统资源。开发者应严格验证输入,禁止使用绝对路径,并采用白名单机制或规范化路径处理,确保最终解析路径始终位于预期的安全沙箱内。
String filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);import os import sys def main(): filename = sys.argv[1] path = os.path.join(os.getcwd(), filename) try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()import os import sys def main(): filename = sys.argv[1] path = os.path.normpath(f"{os.getcwd()}{os.sep}{filename}") if path.startswith("/home/cwe/documents/"): try: with open(path, 'r') as f: file_data = f.read() except FileNotFoundError as e: print("Error - file not found") main()| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-4172 | Chengdu Flash Flood Disaster Monitoring and Warning System 路径遍历漏洞 — Flash Flood Disaster Monitoring and Warning System | 4.3 | Medium | 2023-08-05 |
| CVE-2023-3765 | Mlflow 安全漏洞 — mlflow/mlflow | 4.3 | - | 2023-07-19 |
| CVE-2023-34135 | SonicWALL Analytics和GMS 路径遍历漏洞 — GMS | 6.5 | - | 2023-07-13 |
| CVE-2023-32054 | Microsoft Windows Volume Shadow Copy 安全漏洞 — Windows 10 Version 1809 | 7.3 | High | 2023-07-11 |
| CVE-2023-2765 | Weaver E-Office 安全漏洞 — OA | 4.3 | Medium | 2023-05-17 |
| CVE-2023-2101 | Mogu blog 路径遍历漏洞 — Mogu Blog v2 | 4.3 | Medium | 2023-04-15 |
| CVE-2023-1176 | Mlflow 安全漏洞 — mlflow/mlflow | 7.1 | - | 2023-03-24 |
| CVE-2022-20958 | Cisco BroadWorks CommPilot 代码问题漏洞 — Cisco BroadWorks | 8.3 | High | 2022-11-03 |
| CVE-2022-20791 | Cisco Unified Communications Manager 路径遍历漏洞 — Cisco Unified Communications Manager | 6.5 | Medium | 2022-07-06 |
| CVE-2022-1554 | scout 路径遍历漏洞 — clinical-genomics/scout | 6.5 | - | 2022-05-03 |
| CVE-2021-34711 | Cisco IP Phone 路径遍历漏洞 — Cisco IP Phones with Multiplatform Firmware | 5.5 | Medium | 2021-10-06 |
| CVE-2021-1617 | Cisco Intersight 路径遍历漏洞 — Cisco Intersight Virtual Appliance | 6.5 | Medium | 2021-07-22 |
| CVE-2021-1618 | Cisco Intersight 操作系统命令注入漏洞 — Cisco Intersight Virtual Appliance | 6.5 | Medium | 2021-07-22 |
| CVE-2021-21586 | Dell Wyse Management Suite 路径遍历漏洞 — Wyse Management Suite | 8.1 | High | 2021-07-15 |
| CVE-2021-32507 | QSAN Storage Manager 路径遍历漏洞 — Storage Manager | 6.5 | Medium | 2021-07-07 |
| CVE-2021-32506 | QSAN Storage Manager 路径遍历漏洞 — Storage Manager | 6.5 | Medium | 2021-07-07 |
| CVE-2021-30173 | 竣禾科技全方位通讯系统安全漏洞 — Quan-Fang-Wei-Tong-Xun system | 6.5 | Medium | 2021-05-07 |
| CVE-2021-1296 | 多款Cisco产品路径遍历漏洞 — Cisco Small Business RV Series Router Firmware | 7.5 | High | 2021-02-04 |
| CVE-2021-1297 | 多款Cisco产品路径遍历漏洞 — Cisco Small Business RV Series Router Firmware | 7.5 | High | 2021-02-04 |
| CVE-2018-20250 | WinRar 路径遍历漏洞 — WinRAR | 9.8 | - | 2019-02-05 |
| CVE-2017-7929 | Advantech WebAccess 路径遍历漏洞 — Advantech WebAccess | 4.3 | - | 2017-05-06 |
CWE-36(绝对路径遍历) 是常见的弱点类别,本平台收录该类弱点关联的 111 条 CVE 漏洞。