目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-602 服务端安全的客户端实施 类漏洞列表 109

CWE-602 服务端安全的客户端实施 类弱点 109 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-602 指客户端执行服务端安全机制的漏洞,属于逻辑设计缺陷。攻击者通过修改客户端代码或拦截请求,绕过前端限制直接与服务端交互,从而获取未授权访问或执行恶意操作。开发者应避免依赖前端进行敏感验证,必须确保所有安全控制逻辑均在服务端独立实施,以保障数据完整性与系统安全性。

MITRE CWE 官方描述
CWE:CWE-602 客户端执行服务端安全(Client-Side Enforcement of Server-Side Security) 英文:该产品由一个服务器组成,该服务器依赖客户端来实现旨在保护服务器的机制。 当服务器依赖放置在客户端的保护机制时,攻击者可以修改客户端行为以绕过这些保护机制,从而导致客户端与服务器之间出现潜在的意外交互。后果将因这些机制试图保护的内容不同而有所差异。
常见影响 (2)
Access Control, Availability Bypass Protection Mechanism, DoS: Crash, Exit, or Restart
Client-side validation checks can be easily bypassed, allowing malformed or unexpected input to pass into the application, potentially as trusted data. This may lead to unexpected states, behaviors and possibly a resulting crash.
Access Control Bypass Protection Mechanism, Gain Privileges or Assume Identity
Client-side checks for authentication can be easily bypassed, allowing clients to escalate their access levels and perform unintended actions.
缓解措施 (2)
Architecture and Design For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server. Even though client-side checks provide minim…
Architecture and Design If some degree of trust is required between the two entities, then use integrity checking and strong authentication to ensure that the inputs are coming from a trusted source. Design the product so that this trust is managed in a centralized fashion, especially if there are complex or numerous communication channels, in order to reduce the risks that the implementer will mistakenly omit a check in…
代码示例 (2)
This example contains client-side code that checks if the user authenticated successfully before sending a command. The server-side code performs the authentication in one step, and executes the command in a separate step.
$server = "server.example.com"; $username = AskForUserName(); $password = AskForPassword(); $address = AskForAddress(); $sock = OpenSocket($server, 1234); writeSocket($sock, "AUTH $username $password\n"); $resp = readSocket($sock); if ($resp eq "success") { # username/pass is valid, go ahead and update the info! writeSocket($sock, "CHANGE-ADDRESS $username $address\n"; } else { print "ERROR: Invalid Authentication!\n"; }
Good · Perl
$sock = acceptSocket(1234); ($cmd, $args) = ParseClientRequest($sock); if ($cmd eq "AUTH") { ($username, $pass) = split(/\s+/, $args, 2); $result = AuthenticateUser($username, $pass); writeSocket($sock, "$result\n"); # does not close the socket on failure; assumes the # user will try again } elsif ($cmd eq "CHANGE-ADDRESS") { if (validateAddress($args)) { $res = UpdateDatabaseRecord($username, "address", $args); writeSocket($sock, "SUCCESS\n"); } else { writeSocket($sock, "FAILURE -- address is malformed\n"); } }
Bad · Perl
In 2022, the OT:ICEFALL study examined products by 10 different Operational Technology (OT) vendors. The researchers reported 56 vulnerabilities and said that the products were "insecure by design" [REF-1283]. If exploited, these vulnerabilities often allowed adversaries to change how the products operated, ranging from denial of service to changing the code that the products executed. Since these…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-100306 TDuck表单6.0及以下版本密码绕过漏洞 — tduck-survey-form 5.3 Medium 2026-09-25
CVE-2026-89175 Kingdom Communication Associated Smart Video Intercom System 处理逻辑错误漏洞 — EH3040 5.3 Medium 2026-09-11
CVE-2026-84841 TSI Coop TSI DPDP Consent Management System 处理逻辑错误漏洞 — tsi-dpdp-cms 7.3 High 2026-09-02
CVE-2026-84110 Releasit COD Form & Upsells 处理逻辑错误漏洞 — Releasit COD Form & Upsells 5.3 Medium 2026-09-01
CVE-2026-73267 Stolostron clusterclaims-controller 处理逻辑错误漏洞 — multicluster engine for Kubernetes 2.10 7.7 High 2026-08-21
CVE-2026-77026 Joomla Convert Forms < 5.2.5 客户端控制验证绕过漏洞 — Convert Forms extension for Joomla 6.9 Medium 2026-08-20
CVE-2026-45274 PoxenStudio talebook 处理逻辑错误漏洞 — talebook 6.9 Medium 2026-08-19
CVE-2026-73627 jupyterlab 处理逻辑错误漏洞 — jupyterlab 6.0 Medium 2026-08-13
CVE-2026-59504 Priority Portal Generator 处理逻辑错误漏洞 — Portal Generator addon to Priority ERP (developed by Soft Solutions) 9.1 Critical 2026-08-13
CVE-2026-16480 IBM DB2 处理逻辑错误漏洞 — Db2 4.3 Medium 2026-08-12
CVE-2026-63301 OpenSolution Quick.CMS 处理逻辑错误漏洞 — Quick.CMS 7.0 High 2026-07-28
CVE-2026-64813 JetBrains IntelliJ IDEA 处理逻辑错误漏洞 — IntelliJ IDEA 10.0 Critical 2026-07-23
CVE-2026-65051 WordPress Ninja Forms 处理逻辑错误漏洞 — Ninja Forms 6.5 Medium 2026-07-21
CVE-2026-13724 Gobito Corporate Training Management System 处理逻辑错误漏洞 — Corporate Training Management System 4.3 Medium 2026-07-20
CVE-2025-36327 IBM watsonx.data intelligence 处理逻辑错误漏洞 — watsonx.data intelligence 6.5 Medium 2026-06-30
CVE-2026-57913 Johnson & Johnson Audit Tracking Management System 处理逻辑错误漏洞 — Audit Tracking Management System 7.5 High 2026-06-26
CVE-2026-57912 Johnson & Johnson Campus Recruiting 处理逻辑错误漏洞 — Campus Recruiting 7.5 High 2026-06-26
CVE-2026-56256 Capgo 处理逻辑错误漏洞 — Capgo 7.1 High 2026-06-24
CVE-2026-56693 NanoCo NanoClaw 处理逻辑错误漏洞 — nanoclaw 5.5 Medium 2026-06-23
CVE-2026-54104 Government Accountability Office Electronic Protest Docketing System 处理逻辑错误漏洞 — Electronic Protest Docketing System (EPDS) 8.8 High 2026-06-18
CVE-2026-42329 Iris 安全漏洞 — iris-web 4.7 Medium 2026-06-04
CVE-2026-42160 dataspace-portal 安全漏洞 — dataspace-portal 4.3AI Medium AI 2026-05-08
CVE-2026-39415 Frappe Learning Management System 安全漏洞 — lms 7.1AI High AI 2026-04-08
CVE-2026-25737 Budibase 安全漏洞 — budibase 8.9 High 2026-03-09
CVE-2026-30783 RustDesk 安全漏洞 — RustDesk Client 8.8 - 2026-03-05
CVE-2026-23859 Dell Wyse Management Suite WMS 安全漏洞 — Wyse Management Suite 2.7 Low 2026-02-24
CVE-2025-36410 IBM ApplinX 安全漏洞 — ApplinX 3.1 Low 2026-01-20
CVE-2026-0808 WordPress plugin Spin Wheel 安全漏洞 — Spin Wheel – Interactive spinning wheel that offers coupons 5.3 Medium 2026-01-17
CVE-2026-23478 Cal.com 安全漏洞 — cal.com 9.8AI Critical AI 2026-01-13
CVE-2025-14687 IBM Db2 Intelligence Center 安全漏洞 — Db2 Intelligence Center 4.3 Medium 2025-12-26

CWE-602(服务端安全的客户端实施) 是常见的弱点类别,本平台收录该类弱点关联的 109 条 CVE 漏洞。