目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-494 下载代码缺少完整性检查 类漏洞列表 122

CWE-494 下载代码缺少完整性检查 类弱点 122 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-494指下载代码时未进行完整性校验的漏洞。攻击者常通过劫持传输通道、DNS欺骗或入侵源服务器,篡改下载内容以植入恶意代码。开发者应实施数字签名验证或哈希校验,确保代码来源可信且未被篡改,从而防止执行被操纵的程序,保障系统安全。

MITRE CWE 官方描述
CWE:CWE-494 Download of Code Without Integrity Check 英文:产品从远程位置下载源代码或可执行文件,并在未充分验证代码的来源和完整性的情况下执行该代码。 攻击者可以通过入侵主机服务器、执行 DNS spoofing 或在传输过程中修改代码来执行恶意代码。
常见影响 (1)
Integrity, Availability, Confidentiality, Other Execute Unauthorized Code or Commands, Alter Execution Logic, Other
Executing untrusted code could compromise the control flow of the program. The untrusted code could execute attacker-controlled commands, read or modify sensitive resources, or prevent the software from functioning correctly for legitimate users.
缓解措施 (5)
Implementation Perform proper forward and reverse DNS lookups to detect DNS spoofing.
Architecture and Design, Operation Encrypt the code with a reliable encryption scheme before transmitting. This will only be a partial solution, since it will not detect DNS spoofing and it will not prevent your code from being modified on the hosting site.
Architecture and Design Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid [REF-1482]. Speficially, it may be helpful to use tools or frameworks to perform integrity checking on the transmitted code. When providing the code that is to be downloaded, such as for automatic updates of the software, then use cryptographic signatures for …
Architecture and Design, Operation Run your code using the lowest privileges that are required to accomplish the necessary tasks [REF-76]. If possible, create isolated accounts with limited privileges that are only used for a single task. That way, a successful attack will not immediately give the attacker access to the rest of the software or its environment. For example, database applications rarely need to run as the database ad…
Architecture and Design, Operation Run the code in a "jail" or similar sandbox environment that enforces strict boundaries between the process and the operating system. This may effectively restrict which files can be accessed in a particular directory or which commands can be executed by the software. OS-level examples include the Unix chroot jail, AppArmor, and SELinux. In general, managed code may provide some protection. For ex…
Effectiveness: Limited
代码示例 (2)
This example loads an external class from a local subdirectory.
URL[] classURLs= new URL[]{ new URL("file:subdir/") }; URLClassLoader loader = new URLClassLoader(classURLs); Class loadedClass = Class.forName("loadMe", true, loader);
Bad · Java
This code includes an external script to get database credentials, then authenticates a user against the database, allowing access to the application.
//assume the password is already encrypted, avoiding CWE-312 function authenticate($username,$password){ include("http://external.example.com/dbInfo.php"); //dbInfo.php makes $dbhost, $dbuser, $dbpass, $dbname available mysql_connect($dbhost, $dbuser, $dbpass) or die ('Error connecting to mysql'); mysql_select_db($dbname); $query = 'Select * from users where username='.$username.' And password='.$password; $result = mysql_query($query); if(mysql_numrows($result) == 1){ mysql_close(); return true; } else{ mysql_close(); return false; } }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2017-12740 Siemens LOGO! Soft Comfort 安全漏洞 — Siemens LOGO! Soft Comfort (All versions before V8.2) 5.9 - 2017-12-26
CVE-2014-2378 Sensys Networks VSN240-F/VSN240-T sensors VDS/TrafficDOT 代码注入漏洞 — VSN240-F 7.5 - 2014-09-05

CWE-494(下载代码缺少完整性检查) 是常见的弱点类别,本平台收录该类弱点关联的 122 条 CVE 漏洞。