CWE-502 可信数据的反序列化 类弱点 2188 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }
private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }
try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-29300 | Adobe ColdFusion 代码问题漏洞 — ColdFusion | 9.8 | Critical | 2023-07-12 |
| CVE-2023-36825 | Orchid 代码问题漏洞 — platform | 9.7 | Critical | 2023-07-11 |
| CVE-2023-33160 | Microsoft SharePoint 安全漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2023-07-11 |
| CVE-2023-33134 | Microsoft SharePoint 安全漏洞 — Microsoft SharePoint Enterprise Server 2016 | 8.8 | High | 2023-07-11 |
| CVE-2023-35317 | Microsoft Windows Server Update Service 安全漏洞 — Windows Server 2019 | 7.8 | High | 2023-07-11 |
| CVE-2023-34347 | Delta Electronics InfraSuite Device Master 代码问题漏洞 — Infrasuite Device Master | 9.8 | Critical | 2023-07-10 |
| CVE-2023-33008 | Apache Johnzon 代码问题漏洞 — Apache Johnzon | 7.5 | - | 2023-07-07 |
| CVE-2023-31222 | Medtronic Paceart Optima 代码问题漏洞 — Paceart Optima | 9.8 | Critical | 2023-06-29 |
| CVE-2023-33299 | Fortinet FortiNAC 代码问题漏洞 — FortiNAC | 9.6 | Critical | 2023-06-23 |
| CVE-2023-3308 | whaleal IceFrog 代码问题漏洞 — IceFrog | 5.5 | Medium | 2023-06-18 |
| CVE-2023-32031 | Microsoft Exchange Server 安全漏洞 — Microsoft Exchange Server 2019 Cumulative Update 12 | 8.8 | High | 2023-06-14 |
| CVE-2023-28310 | Microsoft Exchange Server 安全漏洞 — Microsoft Exchange Server 2016 Cumulative Update 23 | 8.0 | High | 2023-06-14 |
| CVE-2023-3001 | Schneider Electric IGSS 代码问题漏洞 — IGSS Dashboard (DashBoard.exe) | 7.8 | High | 2023-06-14 |
| CVE-2023-3234 | Zhongbang CRMEB 代码问题漏洞 — CRMEB | 4.3 | Medium | 2023-06-14 |
| CVE-2023-3232 | Zhongbang CRMEB 代码问题漏洞 — CRMEB | 6.3 | Medium | 2023-06-14 |
| CVE-2023-34212 | Apache NiFi 代码问题漏洞 — Apache NiFi | 8.8 | - | 2023-06-12 |
| CVE-2020-36727 | WordPress Plugin Newsletter Manager 代码问题漏洞 — Newsletter Manager | 9.8 | Critical | 2023-06-07 |
| CVE-2020-36726 | WordPress Plugin Ultimate Reviews 代码问题漏洞 — Ultimate Reviews | 9.8 | Critical | 2023-06-07 |
| CVE-2020-36718 | WordPress Plugin GDPR CCPA Compliance Support 代码问题漏洞 — GDPR CCPA Compliance & Cookie Consent Banner | 9.8 | Critical | 2023-06-07 |
| CVE-2023-33963 | DataEase 代码问题漏洞 — dataease | 9.8 | Critical | 2023-06-01 |
| CVE-2023-2500 | WordPress plugin Go Pricing - WordPress Responsive Pricing Tables 代码问题漏洞 — Go Pricing - WordPress Responsive Pricing Tables | 8.8 | High | 2023-05-24 |
| CVE-2022-4815 | Hitachi Vantara Pentaho Business Analytics Server 代码问题漏洞 — Pentaho Business Analytics Server | 8.0 | High | 2023-05-24 |
| CVE-2023-31058 | Apache InLong 代码问题漏洞 — Apache InLong | 9.8 | - | 2023-05-22 |
| CVE-2023-32336 | IBM InfoSphere Information Server 代码问题漏洞 — InfoSphere Information Server | 8.8 | High | 2023-05-22 |
| CVE-2023-30899 | Siemens Siveillance Video Mobile Server 代码问题漏洞 — Siveillance Video 2020 R2 | 9.9 | Critical | 2023-05-09 |
| CVE-2023-30898 | Siemens Siveillance Video Mobile Server 代码问题漏洞 — Siveillance Video 2020 R2 | 9.9 | Critical | 2023-05-09 |
| CVE-2023-20853 | aEnrich a+HRD 代码问题漏洞 — a+HRD | 9.8 | Critical | 2023-04-27 |
| CVE-2023-20852 | aEnrich a+HRD 代码问题漏洞 — a+HRD | 9.8 | Critical | 2023-04-27 |
| CVE-2023-2141 | Dassault Systèmes DELMIA Apriso 代码问题漏洞 — DELMIA Apriso | 8.5 | High | 2023-04-21 |
| CVE-2023-2042 | DataGear 代码问题漏洞 — DataGear | 6.3 | Medium | 2023-04-14 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 2188 条 CVE 漏洞。