CWE-502 可信数据的反序列化 类弱点 2188 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2022-2446 | WordPress plugin WP Editor 代码问题漏洞 — WP Editor | 7.2 | High | 2024-09-13 |
| CVE-2024-41874 | Adobe ColdFusion 代码问题漏洞 — ColdFusion | 9.8 | Critical | 2024-09-13 |
| CVE-2024-28991 | SolarWinds Access Rights Manager 代码问题漏洞 — Access Rights Manager | 9.0 | Critical | 2024-09-12 |
| CVE-2024-45855 | MindsDB 安全漏洞 — mindsdb | 7.1 | High | 2024-09-12 |
| CVE-2024-45854 | MindsDB 安全漏洞 — mindsdb | 7.1 | High | 2024-09-12 |
| CVE-2024-45853 | MindsDB 安全漏洞 — mindsdb | 7.1 | High | 2024-09-12 |
| CVE-2024-45852 | MindsDB 安全漏洞 — mindsdb | 8.8 | High | 2024-09-12 |
| CVE-2024-45857 | Cleanlab 安全漏洞 — cleanlab | 7.8 | High | 2024-09-12 |
| CVE-2024-43466 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 6.5 | Medium | 2024-09-10 |
| CVE-2024-43464 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 7.2 | High | 2024-09-10 |
| CVE-2024-38018 | Microsoft SharePoint 代码问题漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2024-09-10 |
| CVE-2024-37288 | Elastic Kibana 安全漏洞 — Kibana | 9.9 | Critical | 2024-09-09 |
| CVE-2024-7435 | WordPress plugin Attire 代码问题漏洞 — Attire | 8.8 | High | 2024-08-31 |
| CVE-2024-8016 | WordPress plugin Events Calendar Pro 代码问题漏洞 — The Events Calendar Pro | 9.1 | Critical | 2024-08-30 |
| CVE-2024-2694 | WordPress plugin Betheme 代码问题漏洞 — Betheme | 8.8 | High | 2024-08-30 |
| CVE-2024-8255 | Delta Electronics DTN Soft 代码问题漏洞 — DTN Soft | 9.8AI | Critical AI | 2024-08-29 |
| CVE-2024-43931 | WordPress plugin JobSearch 代码问题漏洞 — JobSearch | 9.8 | Critical | 2024-08-29 |
| CVE-2022-2440 | WordPress plugin Theme Editor 代码问题漏洞 — Theme Editor | 7.2 | High | 2024-08-29 |
| CVE-2024-8030 | WordPress plugin Ultimate Store Kit Elementor Addons, Woocommerce Builder, EDD Builder, Elementor Store Builder, Product Grid, Product Table, Woocommerce Slider 安全漏洞 — Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | 9.8 | Critical | 2024-08-28 |
| CVE-2024-7351 | WordPress plugin Simple Job Board 安全漏洞 — Simple Job Board | 7.2 | High | 2024-08-24 |
| CVE-2024-5335 | WordPress plugin Woo Inquiry 安全漏洞 — Ultimate Store Kit – Addon For WooCommerce, EDD and Elementor | 9.8 | Critical | 2024-08-21 |
| CVE-2024-42362 | Hertzbeat 安全漏洞 — HertzBeat | 8.8 | High | 2024-08-20 |
| CVE-2024-42363 | Samson 安全漏洞 — Samson | 8.8 | High | 2024-08-20 |
| CVE-2024-8003 | gotribe-admin 安全漏洞 — gotribe-admin | 3.5 | Low | 2024-08-20 |
| CVE-2024-5932 | WordPress plugin GiveWP 安全漏洞 — GiveWP – Donation Plugin and Fundraising Platform | 10.0 | Critical | 2024-08-20 |
| CVE-2024-43354 | WordPress plugin myCred 代码问题漏洞 — myCred | 9.8 | Critical | 2024-08-19 |
| CVE-2024-43252 | WordPress plugin Crew HRM 代码问题漏洞 — Crew HRM | 9.0 | Critical | 2024-08-19 |
| CVE-2024-43242 | WordPress plugin Ultimate Membership Pro 代码问题漏洞 — Ultimate Membership Pro | 9.0 | Critical | 2024-08-19 |
| CVE-2024-37099 | WordPress plugin GiveWP 代码问题漏洞 — GiveWP | 10.0 | Critical | 2024-08-19 |
| CVE-2024-28986 | SolarWinds Web Help Desk 代码问题漏洞 — Web Help Desk | 9.8 | Critical | 2024-08-13 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2188 条 CVE 漏洞。