CWE-863 授权机制不正确 类弱点 1383 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-863属于授权检查缺陷,指系统在验证用户访问权限时未能正确执行检查逻辑。攻击者通常利用此漏洞,通过构造恶意请求或篡改参数,绕过权限控制以访问未授权资源或执行敏感操作。开发者应避免此问题,需确保在关键操作前严格验证用户身份与权限,采用最小权限原则,并实施集中式的授权管理,防止逻辑绕过或硬编码错误。
$role = $_COOKIES['role']; if (!$role) { $role = getRole('user'); if ($role) { // save the cookie to send out in future responses setcookie("role", $role, time()+60*60*2); } else{ ShowLoginScreen(); die("\n"); } } if ($role == 'Reader') { DisplayMedicalHistory($_POST['patient_ID']); } else{ die("You are not Authorized to view this record\n"); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-1540 | Cisco ASR 5000授权问题漏洞 — Cisco ASR 5000 Series Software | 8.1 | High | 2021-06-04 |
| CVE-2021-1539 | Cisco ASR 5000授权问题漏洞 — Cisco ASR 5000 Series Software | 8.1 | High | 2021-06-04 |
| CVE-2021-3469 | Foreman 安全漏洞 — Foreman | 6.3 | - | 2021-06-03 |
| CVE-2021-3499 | OVN Kubernetes 安全漏洞 — openshift/ovn-kubernetes | 7.0 | - | 2021-06-02 |
| CVE-2021-20306 | Red Hat BPMN Editor 安全漏洞 — Business-central | 4.3 | - | 2021-06-01 |
| CVE-2020-1729 | SmallRye 安全漏洞 — SmallRye | 4.4 | - | 2021-05-28 |
| CVE-2021-21552 | Dell Wyse Management Suite 安全漏洞 — Wyse Windows Embedded (WES) | 5.2 | Medium | 2021-05-21 |
| CVE-2021-24278 | WordPress plugin 安全漏洞 — Redirection for Contact Form 7 | 7.5 | - | 2021-05-14 |
| CVE-2021-24279 | WordPress plugin 安全漏洞 — Redirection for Contact Form 7 | 6.5 | - | 2021-05-14 |
| CVE-2021-24281 | WordPress 安全漏洞 — Redirection for Contact Form 7 | 6.5 | - | 2021-05-14 |
| CVE-2021-24282 | WordPress plugin 安全漏洞 — Redirection for Contact Form 7 | 6.3 | - | 2021-05-14 |
| CVE-2021-3457 | Foreman 安全漏洞 — smart_proxy_shellhooks | 7.3 | - | 2021-05-12 |
| CVE-2021-24244 | WordPress 安全漏洞 — WPBakery Page Builder (Visual Composer) Clipboard | 6.5 | - | 2021-05-05 |
| CVE-2021-29439 | Grav 安全漏洞 — grav-plugin-admin | 7.2 | High | 2021-04-13 |
| CVE-2021-29437 | Kenny2github ScratchOAuth2 安全漏洞 — ScratchOAuth2 | 8.0 | High | 2021-04-13 |
| CVE-2021-29943 | Apache Solr 安全漏洞 — Apache Solr | 9.1 | - | 2021-04-13 |
| CVE-2020-36287 | Atlassian JIRA Server和Atlassian JIRA Data Center 安全漏洞 — Jira Server | 5.3 | - | 2021-04-09 |
| CVE-2021-24207 | WordPress plugin WP Page Builder 访问控制错误漏洞 — WP Page Builder | 4.3 | - | 2021-04-05 |
| CVE-2020-36238 | Atlassian Jira Server and Data Center 安全漏洞 — Jira Server | 5.3 | - | 2021-04-01 |
| CVE-2021-21411 | OAuth2-Proxy 访问控制错误漏洞 — oauth2-proxy | 5.5 | Medium | 2021-03-26 |
| CVE-2021-21389 | WordPress 安全漏洞 — BuddyPress | 8.1 | High | 2021-03-26 |
| CVE-2021-20283 | Moodle 安全漏洞 — moodle | 4.3 | - | 2021-03-15 |
| CVE-2021-20282 | Moodle 安全漏洞 — moodle | 7.5 | - | 2021-03-15 |
| CVE-2020-25239 | Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect Server | 8.8 | - | 2021-03-15 |
| CVE-2020-25240 | Siemens SINEMA Remote Connect Server 安全漏洞 — SINEMA Remote Connect Server | 8.3 | - | 2021-03-15 |
| CVE-2021-20179 | pki-core 安全漏洞 — pki-core | 7.4 | - | 2021-03-15 |
| CVE-2021-21367 | DanielForé switchboard-plug-bluetooth 安全漏洞 — switchboard-plug-bluetooth | 6.1 | Medium | 2021-03-12 |
| CVE-2021-26563 | Synology DiskStation Manager 访问控制错误漏洞 — DiskStation Manager (DSM) | 8.2 | High | 2021-02-26 |
| CVE-2021-20229 | PostgreSQL 安全漏洞 — PostgreSQL | 4.3 | - | 2021-02-23 |
| CVE-2021-21318 | Opencast 访问控制错误漏洞 — opencast | 5.4 | Medium | 2021-02-18 |
CWE-863(授权机制不正确) 是常见的弱点类别,本平台收录该类弱点关联的 1383 条 CVE 漏洞。