目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-653 不充分的划分 类漏洞列表 48

CWE-653 不充分的划分 类弱点 48 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-653指缺乏适当隔离或分区的漏洞,表现为产品未对需不同权限的功能、进程或资源进行有效隔离。攻击者常利用此缺陷,通过低权限入口突破边界,将破坏范围扩展至高权限用户或核心资源。开发者应实施严格的访问控制与权限分离,确保各组件间具备强边界,防止低特权实体越权访问高特权资源,从而降低整体安全风险。

MITRE CWE 官方描述
CWE:CWE-653 隔离或隔离区(Compartmentalization)不当 英文:产品未能正确地对需要不同特权级别(privilege levels)、权利(rights)或权限(permissions)的功能、进程或资源进行隔离区(compartmentalize)或隔离(isolate)。 当弱点出现在可由低特权用户访问的功能中时,若缺乏强有力的边界(boundaries),攻击可能会将损害范围扩展至更高特权用户。
常见影响 (1)
Access Control Gain Privileges or Assume Identity, Bypass Protection Mechanism
The exploitation of a weakness in low-privileged areas of the software can be leveraged to reach higher-privileged areas without having to overcome any additional obstacles.
缓解措施 (1)
Architecture and Design Break up privileges between different modules, objects, or entities. Minimize the interfaces between modules and require strong access control between them.
代码示例 (2)
Single sign-on technology is intended to make it easier for users to access multiple resources or domains without having to authenticate each time. While this is highly convenient for the user and attempts to address problems with psychological acceptability, it also means that a compromise of a user's credentials can provide immediate access to all other resources or domains.
The traditional UNIX privilege model provides root with arbitrary access to all resources, but root is frequently the only user that has privileges. As a result, administrative tasks require root privileges, even if those tasks are limited to a small area, such as updating user manpages. Some UNIX flavors have a "bin" user that is the owner of system executables, but since root relies on executabl…
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-97029 Flatpak: flatpak: sandboxed app can signal unsandboxed processes in the same process group — Red Hat Enterprise Linux 10 5.7 Medium 2026-09-29
CVE-2026-101078 deepseek-harness Landlock隔离配置缺陷 — deepseek-harness 6.3 Medium 2026-09-28
CVE-2026-95699 MrSteam iSteamX 安全隔离不当漏洞 — iSteamX application 9.6 Critical 2026-09-24
CVE-2026-57135 Mervin Praison PraisonAI 权限许可和访问控制问题漏洞 — PraisonAI 7.6 High 2026-09-15
CVE-2026-15366 Vivo Kids Mode 权限许可和访问控制问题漏洞 — Kids Mode 2.4 Low 2026-08-26
CVE-2026-71325 Traefik 权限许可和访问控制问题漏洞 — traefik 4.8 Medium 2026-08-06
CVE-2026-65635 malach-it Boruta 权限许可和访问控制问题漏洞 — boruta 8.3 High 2026-07-30
CVE-2026-53421 Apache Syncope 权限许可和访问控制问题漏洞 — Apache Syncope - - 2026-07-20
CVE-2026-53405 Apache Syncope 权限许可和访问控制问题漏洞 — Apache Syncope - - 2026-07-20
CVE-2026-63071 Apache Syncope 权限许可和访问控制问题漏洞 — Apache Syncope - - 2026-07-20
CVE-2026-15738 Amazon AWS Load Balancer Controller 权限许可和访问控制问题漏洞 — aws-load-balancer-controller 8.5 High 2026-07-14
CVE-2026-41155 Imagination Technologies Graphics DDK 权限许可和访问控制问题漏洞 — Graphics DDK - - 2026-06-12
CVE-2026-42782 Apache Syncope 安全漏洞 — Apache Syncope - - 2026-05-25
CVE-2026-40968 Vmware Spring gRPC 安全漏洞 — Spring gRPC 4.3 Medium 2026-04-28
CVE-2026-5600 pretix 安全漏洞 — pretix 4.3AI Medium AI 2026-04-08
CVE-2026-5599 venueless 安全漏洞 — Venueless 6.5AI Medium AI 2026-04-05
CVE-2026-34775 Electron 安全漏洞 — electron 6.8 Medium 2026-04-03
CVE-2026-4325 Keycloak 安全漏洞 — Red Hat build of Keycloak 26.2 5.3 Medium 2026-04-02
CVE-2026-4282 Keycloak 安全漏洞 — Red Hat build of Keycloak 26.2 7.4 High 2026-04-02
CVE-2025-12805 Llama Stack 安全漏洞 — Red Hat OpenShift AI 2.25 8.1 High 2026-03-26
CVE-2026-0542 ServiceNow AI Platform 安全漏洞 — ServiceNow AI Platform 9.8AI Critical AI 2026-02-25
CVE-2026-25905 Pydantic 安全漏洞 5.8 Medium 2026-02-09
CVE-2025-53710 Palantir Foundry Container Service 安全漏洞 — com.palantir.compute:compute-service 7.5 High 2025-12-18
CVE-2025-46215 Fortinet FortiSandbox 安全漏洞 — FortiSandbox 5.0 Medium 2025-11-18
CVE-2025-41116 Grafana Databricks Datasource Plugin 安全漏洞 — Grafana Databricks Datasource Plugin 7.5 - 2025-11-11
CVE-2025-3717 Grafana Snowflake Datasource Plugin 安全漏洞 — Grafana Snowflake Datasource Plugin 5.3 - 2025-11-11
CVE-2025-12695 dspy 安全漏洞 5.9 Medium 2025-11-04
CVE-2025-57738 Apache Syncope 安全漏洞 — Apache Syncope 7.2AI High AI 2025-10-20
CVE-2025-34201 Vasion Print和Vasion Print Virtual Appliance Host 安全漏洞 — Print Virtual Appliance Host 9.6 - 2025-09-19
CVE-2025-41688 MB connect line mbNET 安全漏洞 — mbNET HW1 7.2 High 2025-07-31

CWE-653(不充分的划分) 是常见的弱点类别,本平台收录该类弱点关联的 48 条 CVE 漏洞。