目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-942 过度许可的跨域白名单 类漏洞列表 91

CWE-942 过度许可的跨域白名单 类弱点 91 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-942属于跨域安全策略配置错误漏洞。当Web应用允许与不受信任的域进行通信时,攻击者可利用该缺陷通过恶意域窃取敏感数据或执行未授权操作。开发者应避免在内容安全策略或跨域策略文件中包含通配符或不可信域名,严格限制允许通信的源,确保仅信任已知且安全的域,从而防止跨域数据泄露。

MITRE CWE 官方描述
CWE:CWE-942 对不受信任域采用宽松跨域安全策略 产品使用了 Web 客户端保护机制,例如内容安全策略(Content Security Policy, CSP)或跨域策略文件,但该策略包含了允许 Web 客户端与之通信的不受信任域。 如果跨域策略文件包含了不应被信任的域,例如在高阶域下使用通配符时,则应用程序可能受到这些不受信任域的攻击。在许多情况下,攻击可以在受害者毫无察觉的情况下发起。
常见影响 (1)
Confidentiality, Integrity, Availability, Access Control Execute Unauthorized Code or Commands, Bypass Protection Mechanism, Read Application Data, Varies by Context
With an overly permissive policy file, an attacker may be able to bypass the web browser's same-origin policy and conduct many of the same attacks seen in Cross-Site Scripting (CWE-79). An attacker can exploit the weakness to transfer private information from the victim's machine to the attacker, ma…
缓解措施 (3)
Architecture and Design, Operation Define a restrictive Content Security Policy [REF-1486] or cross-domain policy file.
Architecture and Design, Operation Avoid using wildcards in the CSP / cross-domain policy file. Any domain matching the wildcard expression will be implicitly trusted, and can perform two-way interaction with the target server.
Architecture and Design, Operation For Flash, modify crossdomain.xml to use meta-policy options such as 'master-only' or 'none' to reduce the possibility of an attacker planting extraneous cross-domain policy files on a server.
代码示例 (1)
These cross-domain policy files mean to allow Flash and Silverlight applications hosted on other domains to access its data:
<cross-domain-policy xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:noNamespaceSchemaLocation="http://www.adobe.com/xml/schemas/PolicyFile.xsd"> <allow-access-from domain="*.example.com"/> <allow-access-from domain="*"/> </cross-domain-policy>
Bad · XML
<?xml version="1.0" encoding="utf-8"?> <access-policy> <cross-domain-access> <policy> <allow-from http-request-headers="SOAPAction"> <domain uri="*"/> </allow-from> <grant-to> <resource path="/" include-subpaths="true"/> </grant-to> </policy> </cross-domain-access> </access-policy>
Bad · XML
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-66070 RabbitMQ CORS允许凭证反射Origin漏洞 — rabbitmq-server 7.6 High 2026-09-23
CVE-2026-90882 任意源反射致跨域读取认证数据 — open-vsx.org 8.7 High 2026-09-22
CVE-2026-56595 HCL BigFix Service Management 多个安全漏洞 — HCL BigFix Service Management 3.1 Low 2026-09-18
CVE-2026-92359 ag-ui-protocol跨域策略绕过漏洞 — ag-ui 3.1 Low 2026-09-16
CVE-2026-62895 Microsoft Azure Arc 授权问题漏洞 — Azure Arc SQL Server Extension 8.8 High 2026-09-08
CVE-2026-12962 ASUS Armoury Crate 配置错误漏洞 — Armoury Crate 5.3 Medium 2026-09-08
CVE-2026-84452 Microsoft Windows ML CLI 授权问题漏洞 — winml-cli 8.6 High 2026-09-02
CVE-2026-82291 HeyForm 配置错误漏洞 — heyform 8.1 High 2026-08-28
CVE-2026-82287 Rybbit 配置错误漏洞 — rybbit 8.1 High 2026-08-28
CVE-2026-63407 Grav API Plugin 配置错误漏洞 — grav-plugin-api 8.2 High 2026-08-19
CVE-2026-68517 Nicolas Hennion Glances 配置错误漏洞 — glances 6.5 Medium 2026-08-17
CVE-2026-74881 jahlives openssl_encrypt 配置错误漏洞 — openssl_encrypt 6.5 Medium 2026-08-17
CVE-2026-70604 Electron 配置错误漏洞 — electron 7.4 High 2026-08-05
CVE-2026-15966 Progress MOVEit Transfer 配置错误漏洞 — MOVEit Transfer 7.5 High 2026-07-23
CVE-2026-21761 HCL DevOps Loop 配置错误漏洞 — DevOps Loop 4.2 Medium 2026-07-17
CVE-2024-23578 HCL Aftermarket EPC 配置错误漏洞 — Aftermarket EPC 4.2 Medium 2026-07-17
CVE-2026-62387 getgrav Grav 配置错误漏洞 — grav 7.1 High 2026-07-17
CVE-2026-61736 HKUDS LightRAG 配置错误漏洞 — LightRAG 9.3 Critical 2026-07-15
CVE-2026-8919 ASUS GameSDK 配置错误漏洞 — GameSDK 7.2 High 2026-07-15
CVE-2026-56458 HCLSoftware HCL DevOps Deploy 配置错误漏洞 — HCL DevOps Deploy 5.4 Medium 2026-07-09
CVE-2026-55110 Ubiquiti UniFi OS Server 配置错误漏洞 — UniFi OS Server 7.5 High 2026-07-02
CVE-2026-12084 IBM DevOps Deploy 配置错误漏洞 — UCD - IBM DevOps Deploy 5.4 Medium 2026-06-30
CVE-2026-57957 Papermark 配置错误漏洞 — papermark 4.7 Medium 2026-06-29
CVE-2026-54290 honojs hono 配置错误漏洞 — hono 7.1 High 2026-06-22
CVE-2026-56076 PraisonAI 配置错误漏洞 — PraisonAI 8.1 High 2026-06-18
CVE-2026-50088 Aqara Developer Portal 配置错误漏洞 — Aqara Developer Portal 8.2 High 2026-06-12
CVE-2026-50087 Aqara IAM/SSO Gateway 配置错误漏洞 — Aqara IAM/SSO Gateway 8.2 High 2026-06-12
CVE-2026-10056 Network Optix Nx Witness VMS 安全漏洞 — Nx Witness VMS 7.5 High 2026-05-29
CVE-2026-9739 Google MCP Toolbox for Databases 安全漏洞 — MCP Toolbox for Databases - - 2026-05-27
CVE-2026-46431 algernon 安全漏洞 — algernon 4.3 Medium 2026-05-26

CWE-942(过度许可的跨域白名单) 是常见的弱点类别,本平台收录该类弱点关联的 91 条 CVE 漏洞。