目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类漏洞列表 638

CWE-59 在文件访问前对链接解析不恰当(链接跟随) 类弱点 638 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-59 属于文件访问类漏洞,指程序在访问文件前未正确验证链接解析结果。攻击者常通过创建指向敏感资源的符号链接或快捷方式,诱导程序读取非预期文件,从而引发信息泄露或权限提升。开发者应避免直接使用用户输入的文件名,需在访问前校验最终解析路径,确保其位于预期的安全目录内,防止链接劫持风险。

MITRE CWE 官方描述
CWE:CWE-59 文件访问前链接解析不当('Link Following') 英文:产品尝试基于文件名访问文件,但未能正确防止该文件名标识解析到非预期资源的链接或快捷方式。
常见影响 (2)
Confidentiality, Integrity, Access Control Read Files or Directories, Modify Files or Directories, Bypass Protection Mechanism
An attacker may be able to traverse the file system to unintended locations and read or overwrite the contents of unexpected files. If the files are used for a security mechanism then an attacker may be able to bypass the mechanism.
Other Execute Unauthorized Code or Commands
Windows simple shortcuts, sometimes referred to as soft links, can be exploited remotely since a ".LNK" file can be uploaded like a normal file. This can enable remote execution.
缓解措施 (1)
Architecture and Design Follow the principle of least privilege when assigning access rights to entities in a software system. Denying access to a file can prevent an attacker from replacing that file with a link to a sensitive file. Ensure good compartmentalization in the system to provide protected areas that can be trusted.
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-21760 Microsoft Windows Print Spooler Components 安全漏洞 — Windows 10 Version 1809 7.1 High 2023-01-10
CVE-2023-21725 Microsoft Windows 竞争条件问题漏洞 — Windows Malicious Software Removal Tool 6.3 Medium 2023-01-10
CVE-2023-21678 Microsoft Windows 安全漏洞 — Windows 10 Version 1809 7.8 High 2023-01-10
CVE-2023-21542 Microsoft Windows Installer 安全漏洞 — Windows 10 Version 1507 7.0 High 2023-01-10
CVE-2022-4563 SecureDrop 安全漏洞 — SecureDrop 7.8 High 2022-12-16
CVE-2022-4122 Bulidah 后置链接漏洞 — podman 5.3 - 2022-12-08
CVE-2022-31256 systemd 后置链接漏洞 — openSUSE Factory 7.7 High 2022-10-26
CVE-2022-38699 ASUS Armoury Crate Service 后置链接漏洞 — Armoury Crate Service 5.9 Medium 2022-09-28
CVE-2022-0029 Palo Alto Networks Cortex XDR 后置链接漏洞 — Cortex XDR Agent 5.5 Medium 2022-09-14
CVE-2022-2898 Measuresoft ScadaPro Server and Client 后置链接漏洞 — ScadaPro Server and Client 6.1 Medium 2022-08-31
CVE-2022-2897 Measuresoft ScadaPro Server and Client 后置链接漏洞 — ScadaPro Server and Client 7.8 High 2022-08-31
CVE-2021-35939 rpm 后置链接漏洞 — RPM 6.7 - 2022-08-26
CVE-2021-35937 rpm 安全漏洞 — RPM 6.4 - 2022-08-25
CVE-2021-35938 rpm 后置链接漏洞 — RPM 6.7 - 2022-08-25
CVE-2021-23177 libarchive 后置链接漏洞 — libarchive 7.8 - 2022-08-23
CVE-2021-31566 libarchive 后置链接漏洞 — libarchive 7.8 - 2022-08-23
CVE-2022-31250 openSUSE Tumbleweed 后置链接漏洞 — Tumbleweed 7.1 High 2022-07-20
CVE-2022-31219 ABB Mint WorkBench 后置链接漏洞 — Drive Composer entry 7.3 High 2022-06-15
CVE-2022-31218 ABB Automation 后置链接漏洞 — Drive Composer entry 7.8 High 2022-06-15
CVE-2022-31217 ABB Drive Composer 后置链接漏洞 — Drive Composer entry 7.8 High 2022-06-15
CVE-2022-31216 ABB Drive Composer 后置链接漏洞 — Drive Composer entry 7.8 High 2022-06-15
CVE-2021-44052 QNAP多款产品后置链接漏洞 — QuTScloud 6.5 Medium 2022-05-05
CVE-2022-22995 Western Digital My Cloud 后置链接漏洞 — My Cloud 10.0 Critical 2022-03-25
CVE-2022-22262 Asus Rog Live Service 后置链接漏洞 — Armoury Crate & Aura Creator Installer (ROG Live Service) 7.7 High 2022-03-01
CVE-2021-44730 snapd 后置链接漏洞 — snapd 7.8 High 2022-02-17
CVE-2022-0017 GlobalProtect 后置链接漏洞 — GlobalProtect App 7.0 High 2022-02-10
CVE-2022-21944 SUSE Linux Enterprise Server 后置链接漏洞 — openSUSE Backports SLE-15-SP3 7.8 High 2022-01-26
CVE-2022-0012 Palo Alto Networks Cortex XDR 后置链接漏洞 — Cortex XDR Agent 6.1 Medium 2022-01-12
CVE-2021-3641 Bitdefender Endpoint Security Tool 后置链接漏洞 — GravityZone 6.1 Medium 2021-11-09
CVE-2021-31843 McAfee Endpoint Security 后置链接漏洞 — McAfee Endpoint Security (ENS) for WIndows 7.3 High 2021-09-17

CWE-59(在文件访问前对链接解析不恰当(链接跟随)) 是常见的弱点类别,本平台收录该类弱点关联的 638 条 CVE 漏洞。