CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 638 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-7216 | cpio 后置链接漏洞 — Red Hat Enterprise Linux 6 | 5.3 | Medium | 2024-02-05 |
| CVE-2023-6336 | HYPR 后置链接漏洞 — Workforce Access | 7.2 | High | 2024-01-16 |
| CVE-2023-6335 | HYPR 后置链接漏洞 — Workforce Access | 6.4 | Medium | 2024-01-16 |
| CVE-2023-42137 | PAX Technology Android based POS 后置链接漏洞 — POS terminals | 7.8 | High | 2024-01-15 |
| CVE-2023-31003 | IBM Security Access Manager Appliance 安全漏洞 — Security Verify Access Appliance | 8.4 | High | 2024-01-11 |
| CVE-2024-20656 | Microsoft Visual Studio 安全漏洞 — Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) | 7.8 | High | 2024-01-09 |
| CVE-2024-0206 | Trellix Anti-Malware Engine 后置链接漏洞 — Anti-Malware Engine | 7.1 | High | 2024-01-09 |
| CVE-2023-35624 | Microsoft Azure Connected Machine Agent 安全漏洞 — Azure Connected Machine Agent | 7.3 | High | 2023-12-12 |
| CVE-2023-35633 | Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2023-12-12 |
| CVE-2023-36391 | Microsoft Windows Local Security Authority Subsystem Service 安全漏洞 — Windows 11 version 22H3 | 7.8 | High | 2023-12-12 |
| CVE-2023-43590 | Zoom Rooms 后置链接漏洞 — Zoom Rooms for macOS | 7.8 | High | 2023-11-14 |
| CVE-2023-36047 | Microsoft Windows Authentication Methods 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2023-11-14 |
| CVE-2023-36046 | Microsoft Windows Authentication Methods 安全漏洞 — Windows 11 version 21H2 | 7.1 | High | 2023-11-14 |
| CVE-2023-36394 | Microsoft Windows Search Component 安全漏洞 — Windows 10 Version 1809 | 7.0 | High | 2023-11-14 |
| CVE-2023-36399 | Microsoft Windows Storage 安全漏洞 — Windows Server 2022, 23H2 Edition (Server Core installation) | 7.1 | High | 2023-11-14 |
| CVE-2023-36705 | Microsoft Windows Installer 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2023-11-14 |
| CVE-2023-6069 | Froxlor 后置链接漏洞 — froxlor/froxlor | 9.9 | Critical | 2023-11-10 |
| CVE-2023-28797 | Zscaler Client Connector 后置链接漏洞 — Client Connector | 6.3 | Medium | 2023-10-23 |
| CVE-2023-36568 | Microsoft Office 安全漏洞 — Microsoft Office 2019 | 7.0 | High | 2023-10-10 |
| CVE-2023-36711 | Microsoft Windows Runtime C++ Template Library 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2023-10-10 |
| CVE-2023-36723 | Microsoft Windows Container Manager Service 安全漏洞 — Windows 10 Version 1809 | 7.8 | High | 2023-10-10 |
| CVE-2023-36737 | Microsoft Azure 安全漏洞 — Azure Network Watcher VM Extension | 7.8 | High | 2023-10-10 |
| CVE-2023-45159 | 1E Client 后置链接漏洞 — 1E Client | 8.4 | High | 2023-10-05 |
| CVE-2023-32182 | SUSE Linux Enterprise Desktop 后置链接漏洞 — SUSE Linux Enterprise Desktop 15 SP5 | 5.9 | Medium | 2023-09-19 |
| CVE-2023-36758 | Microsoft Visual Studio 安全漏洞 — Microsoft Visual Studio 2022 version 17.7 | 7.8 | High | 2023-09-12 |
| CVE-2023-4759 | Eclipse JGit 安全漏洞 — Eclipse JGit | 8.8 | High | 2023-09-12 |
| CVE-2023-32163 | Wacom driver 后置链接漏洞 — Drivers for Windows | 7.8 | - | 2023-09-06 |
| CVE-2023-38175 | Microsoft Windows Defender 安全漏洞 — Windows Defender Antimalware Platform | 7.8 | High | 2023-08-08 |
| CVE-2023-35379 | Microsoft Windows 安全漏洞 — Windows Server 2008 R2 Service Pack 1 | 7.8 | High | 2023-08-08 |
| CVE-2023-36903 | Microsoft Windows System Assessment Tool 安全漏洞 — Windows 10 Version 1507 | 7.8 | High | 2023-08-08 |
CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 638 条 CVE 漏洞。