目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-668 将资源暴露给错误范围 类漏洞列表 157

CWE-668 将资源暴露给错误范围 类弱点 157 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-668指资源暴露至错误控制域,属访问控制缺陷。攻击者常利用不安全的文件权限或程序逻辑错误,获取本应受限的资源访问权,导致敏感数据泄露或系统被篡改。开发者应严格实施最小权限原则,确保资源仅对授权主体开放,并加强输入验证与对象引用检查,防止程序错误操作非预期对象,从而有效规避此类风险。

MITRE CWE 官方描述
CWE:CWE-668 资源暴露至错误的控制域(Exposure of Resource to Wrong Sphere) 英文:产品将资源暴露至错误的控制域(control sphere),导致非预期的行为主体(actors)获得对该资源的不当访问权限。 文件和目录等资源可能因不安全的权限设置,或程序意外操作了错误的对象,而通过某些机制被无意暴露。例如,程序可能旨在确保私有文件仅向特定用户开放。这实际上定义了一个控制域(control sphere),其意图是防止攻击者访问这些私有文件。如果文件权限不安全,则除该用户之外的其他方也将能够访问这些文件。另一个独立的控制域(control sphere)可能有效要求用户只能访问私有文件,而不能访问系统中的任何其他文件。如果程序未确保用户仅请求私有文件,则用户可能能够访问系统中的其他文件。无论哪种情况,最终结果都是资源被暴露给了错误的主体。
常见影响 (3)
Confidentiality Read Application Data
An adversary that gains access to a resource exposed to a wrong sphere could potentially retrieve private data from that resource, thus breaking the intended confidentiality of that data.
Integrity Modify Application Data
An adversary that gains access to a resource exposed to a wrong sphere could potentially modify data held within that resource, thus breaking the intended integrity of that data and causing the system relying on that resource to make unintended decisions.
Other Varies by Context
The consequences may vary widely depending on how the product uses the affected resource.
CVE ID 标题 CVSS 风险等级 Published
CVE-2022-24074 Naver Whale Browser 安全漏洞 — NAVER Whale browser 9.8 - 2022-03-17
CVE-2022-0815 Mcafee WebAdvisor 访问控制错误漏洞 — McAfee WebAdvisor 6.5 Medium 2022-03-10
CVE-2022-26355 Citrix Virtual Apps and Desktops 安全漏洞 — Federated Authentication Service (FAS) 4.4 - 2022-03-09
CVE-2021-21878 Lantronix PremierWave 2050 输入验证错误漏洞 — Lantronix 4.9 - 2021-12-22
CVE-2021-44524 Siemens SiPass Integrated和Siveillance Identity 授权问题漏洞 — SiPass integrated V2.76 9.1 - 2021-12-14
CVE-2021-44523 Siemens SiPass Integrated和Siveillance Identity 安全漏洞 — SiPass integrated V2.76 9.1 - 2021-12-14
CVE-2021-44522 Siemens SiPass Integrated和Siveillance Identity 安全漏洞 — SiPass integrated V2.76 7.5 - 2021-12-14
CVE-2021-41140 Discourse 信息泄露漏洞 — discourse-reactions 5.3 Medium 2021-10-19
CVE-2021-39184 Electron 安全漏洞 — electron 6.8 Medium 2021-10-12
CVE-2021-40496 Sap Internet Communication Framework 访问控制错误漏洞 — SAP NetWeaver AS ABAP and ABAP Platform 5.3 - 2021-10-12
CVE-2021-41094 Wire 安全漏洞 — wire-ios 4.2 Medium 2021-10-04
CVE-2021-22869 GitHub Enterprise Server 授权问题漏洞 — GitHub Enterprise Server 9.8 - 2021-09-24
CVE-2021-41088 Github elvish 访问控制错误漏洞 — elvish 8.0 High 2021-09-23
CVE-2021-34723 Cisco IOS XE SD-WAN Software 安全漏洞 — Cisco IOS XE Software 6.7 Medium 2021-09-23
CVE-2021-39212 Imagemagick Studio ImageMagick 竞争条件问题漏洞 — ImageMagick 4.4 Medium 2021-09-13
CVE-2021-32788 Discourse 安全漏洞 — discourse 4.3 Medium 2021-07-27
CVE-2021-32760 Apache Containerd 权限许可和访问控制问题漏洞 — containerd 5.0 Medium 2021-07-19
CVE-2021-21382 Restund 安全漏洞 — restund 8.6 High 2021-06-11
CVE-2021-20999 Weidmuller UC20-WL2000-AC 安全漏洞 — UC20-WL2000-AC (No. 1334950000) 9.4 Critical 2021-05-13
CVE-2021-1438 Cisco Wide Area Application Services 安全漏洞 — Cisco Wide Area Application Services (WAAS) 5.5 Medium 2021-05-06
CVE-2021-1423 Cisco Aironet Access Points 安全漏洞 — Cisco Aironet Access Point Software 4.4 Medium 2021-03-24
CVE-2021-21334 containerd 安全漏洞 — containerd 6.3 Medium 2021-03-10
CVE-2020-26272 Electron 安全漏洞 — electron 5.4 Medium 2021-01-28
CVE-2020-26261 JupyterHub 安全漏洞 — systemdspawner 7.9 High 2020-12-09
CVE-2020-26086 Cisco?TelePresence Collaboration Endpoint 访问控制错误漏洞 — Cisco TelePresence Endpoint Software (TC/CE) 4.3 Medium 2020-11-06
CVE-2020-26084 Cisco?Edge Fog Fabric 授权问题漏洞 — Cisco Edge Fog Fabric 6.5 Medium 2020-11-06
CVE-2020-15264 Chocolatey Boxstarter 安全漏洞 — boxstarter 8.0 High 2020-10-20
CVE-2020-16212 Patient Information 安全漏洞 — Patient Information Center iX (PICiX) 8.8 - 2020-09-11
CVE-2020-5386 Dell EMC ECS 安全漏洞 — Elastic Cloud Storage 7.5 - 2020-09-02
CVE-2020-12020 Baxter ExactaMix EM2400和ExactaMix EM1200 安全漏洞 — Baxter ExactaMix EM 2400 & EM 1200 3.3 - 2020-06-29

CWE-668(将资源暴露给错误范围) 是常见的弱点类别,本平台收录该类弱点关联的 157 条 CVE 漏洞。