目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 638

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 638 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-36876 Microsoft Reliability Analysis Metrics Calculation Engine 安全漏洞 — Windows Server 2008 R2 Service Pack 1 7.1 High 2023-08-08
CVE-2023-32056 Microsoft Windows Server Update Service 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-32053 Microsoft Windows Installer 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-36874 Microsoft Windows Error Reporting 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-35353 Microsoft Windows Connected User Experiences and Telemetry 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-35347 Microsoft Windows App Store 安全漏洞 — Windows Server 2022 7.1 High 2023-07-11
CVE-2023-35342 Microsoft Windows Image Acquisition 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-35320 Microsoft Windows Connected User Experiences and Telemetry 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-07-11
CVE-2023-32050 Microsoft Windows Installer 安全漏洞 — Windows Server 2008 Service Pack 2 7.0 High 2023-07-11
CVE-2023-33148 Microsoft Office 安全漏洞 — Microsoft Office 2013 Click-to-Run (C2R) 7.8 High 2023-07-11
CVE-2023-32012 Microsoft Windows Container Manager Service 安全漏洞 — Windows 11 version 21H2 7.8 High 2023-06-13
CVE-2023-29351 Microsoft Windows Group Policy 安全漏洞 — Windows 10 Version 1809 8.1 High 2023-06-13
CVE-2023-24904 Microsoft Windows Installer 安全漏洞 — Windows Server 2008 Service Pack 2 7.1 High 2023-05-09
CVE-2023-29343 Microsoft SysInternals 安全漏洞 — Windows Sysmon 7.8 High 2023-05-09
CVE-2023-28141 Qualys Cloud Agent 安全漏洞 — Cloud Agent 6.7 Medium 2023-04-18
CVE-2023-28972 Juniper Networks Paragon Active Assurance 后置链接漏洞 — Junos OS 6.8 Medium 2023-04-17
CVE-2023-28222 Microsoft Windows Kernel 安全漏洞 — Windows 10 Version 1809 7.1 High 2023-04-11
CVE-2023-0652 Cloudflare WARP 后置链接漏洞 — WARP 7.0 High 2023-04-06
CVE-2023-1412 Cloudflare WARP 后置链接漏洞 — WARP 7.0 High 2023-04-05
CVE-2023-25940 Dell PowerScale OneFS 后置链接漏洞 — PowerScale OneFS 6.7 Medium 2023-04-04
CVE-2023-1314 Cloudflare cloudflared 后置链接漏洞 — cloudflared 7.5 High 2023-03-21
CVE-2023-24930 Microsoft OneDrive 安全漏洞 — OneDrive for MacOS Installer 7.8 High 2023-03-14
CVE-2023-21567 Microsoft Visual Studio 安全漏洞 — Microsoft Visual Studio 2017 version 15.9 (includes 15.0 - 15.8) 5.6 Medium 2023-02-14
CVE-2023-22490 Git 后置链接漏洞 — git 5.5 Medium 2023-02-14
CVE-2023-21722 Microsoft .NET Framework 安全漏洞 — Microsoft .NET Framework 2.0 Service Pack 2 5.0 Medium 2023-02-14
CVE-2023-25168 Wings 后置链接漏洞 — wings 9.6 Critical 2023-02-08
CVE-2023-25152 Wings 后置链接漏洞 — wings 8.4 High 2023-02-08
CVE-2022-42292 NVIDIA GeForce Experience 后置链接漏洞 — GeForce Experience 5.0 Medium 2023-02-07
CVE-2023-20008 Cisco TelePresence Collaboration Endpoint Software 安全漏洞 — Cisco RoomOS Software 4.4 Medium 2023-01-19
CVE-2022-45440 Zyxel AX7501-B0 后置链接漏洞 — AX7501-B0 firmware 4.4 Medium 2023-01-17

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 638 条 CVE 漏洞。