CWE-863 授权机制不正确 类弱点 1383 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-863属于授权检查缺陷,指系统在验证用户访问权限时未能正确执行检查逻辑。攻击者通常利用此漏洞,通过构造恶意请求或篡改参数,绕过权限控制以访问未授权资源或执行敏感操作。开发者应避免此问题,需确保在关键操作前严格验证用户身份与权限,采用最小权限原则,并实施集中式的授权管理,防止逻辑绕过或硬编码错误。
$role = $_COOKIES['role']; if (!$role) { $role = getRole('user'); if ($role) { // save the cookie to send out in future responses setcookie("role", $role, time()+60*60*2); } else{ ShowLoginScreen(); die("\n"); } } if ($role == 'Reader') { DisplayMedicalHistory($_POST['patient_ID']); } else{ die("You are not Authorized to view this record\n"); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-20188 | Podman 访问控制错误漏洞 — podman | 7.0 | - | 2021-02-11 |
| CVE-2021-21286 | Wwbn Avideo 权限许可和访问控制问题漏洞 — AVideo | 7.7 | High | 2021-02-01 |
| CVE-2021-21276 | Cydrobolt Polr 安全漏洞 — polr | 9.3 | Critical | 2021-02-01 |
| CVE-2020-1725 | Red Hat Keycloak 访问控制错误漏洞 — keycloak | 5.4 | - | 2021-01-28 |
| CVE-2021-21013 | Adobe Bridge 缓冲区错误漏洞 — Magento Commerce | 8.1 | High | 2021-01-13 |
| CVE-2021-1144 | Cisco Connected Mobile Experiences 访问控制错误漏洞 — Cisco Connected Mobile Experiences | 8.8 | High | 2021-01-13 |
| CVE-2021-1143 | Cisco Connected Mobile Experiences (CMX) 访问控制错误漏洞 — Cisco Connected Mobile Experiences | 4.3 | Medium | 2021-01-13 |
| CVE-2020-26250 | JupyterHub Oauthenticator 安全漏洞 — oauthenticator | 6.3 | Medium | 2020-12-01 |
| CVE-2020-15248 | October CMS 权限许可和访问控制问题漏洞 — october | 4.0 | Medium | 2020-11-23 |
| CVE-2020-15246 | October CMS 路径遍历漏洞 — october | 7.5 | High | 2020-11-23 |
| CVE-2020-28211 | Schneider Electric EcoStruxure Control Expert 权限许可和访问控制问题漏洞 — PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) | 7.8 | - | 2020-11-19 |
| CVE-2020-25699 | Moodle 访问控制错误漏洞 — moodle | 7.5 | - | 2020-11-19 |
| CVE-2020-26223 | Spree 安全漏洞 — spree | 7.7 | High | 2020-11-13 |
| CVE-2020-25655 | Red Hat Advanced Cluster Management 安全漏洞 — open-cluster-management | 5.7 | Medium | 2020-11-09 |
| CVE-2020-24401 | Adobe Magento 安全漏洞 — Magento Commerce | 6.5 | Medium | 2020-11-09 |
| CVE-2020-15278 | Red Discord Bot 安全漏洞 — Red-DiscordBot | 7.7 | High | 2020-10-28 |
| CVE-2020-3578 | Cisco Firepower Threat Defense和Cisco Adaptive Security Appliances Software 安全漏洞 — Cisco Adaptive Security Appliance (ASA) Software | 5.3 | Medium | 2020-10-21 |
| CVE-2020-12503 | RocketLinx 输入验证错误漏洞 — P+F Comtrol RocketLinx | 7.2 | High | 2020-10-15 |
| CVE-2020-15251 | Sopel Channelmgnt 安全漏洞 — sopel-channelmgnt | 7.7 | High | 2020-10-13 |
| CVE-2020-3467 | Cisco Identity Services Engine 安全漏洞 — Cisco Identity Services Engine Software | 8.5 | - | 2020-10-08 |
| CVE-2020-3404 | Cisco IOS XE 安全漏洞 — Cisco IOS XE Software | 7.8 | - | 2020-09-24 |
| CVE-2020-15163 | Python 数据伪造问题漏洞 — tuf | 8.7 | High | 2020-09-09 |
| CVE-2020-5418 | Cloud Foundry 安全漏洞 — CAPI | 4.3 | - | 2020-09-03 |
| CVE-2020-7300 | McAfee Data Loss Prevention ePO extension 授权问题漏洞 — DLP ePO extension | 4.6 | Medium | 2020-08-12 |
| CVE-2020-15120 | I hate money 安全漏洞 — ihatemoney | 4.9 | Medium | 2020-07-27 |
| CVE-2020-15126 | parser-server 安全漏洞 — parse-server | 6.5 | Medium | 2020-07-22 |
| CVE-2020-15110 | jupyterhub-kubespawner 安全漏洞 — kubespawner | 6.8 | Medium | 2020-07-17 |
| CVE-2020-7499 | 多款Schneider Electric产品访问控制错误漏洞 — U.motion Servers and Touch Panels (affected versions listed in the security notification) | 6.5 | - | 2020-06-16 |
| CVE-2020-11844 | 多款Micro Focus产品Container Deployment Foundation组件安全漏洞 — Hybrid Cloud Management | 10.0 | Critical | 2020-05-29 |
| CVE-2020-6214 | SAP S/4HANA 安全漏洞 — SAP S/4HANA (Financial Products Subledger) | 6.3 | - | 2020-04-14 |
CWE-863(授权机制不正确) 是常见的弱点类别,本平台收录该类弱点关联的 1383 条 CVE 漏洞。