CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3717 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-25154 | FileCatalyst Direct 安全漏洞 — FileCatalyst | 5.3 | Medium | 2024-03-13 |
| CVE-2024-27317 | Apache Pulsar 路径遍历漏洞 — Apache Pulsar | 8.4 | High | 2024-03-12 |
| CVE-2024-21400 | Microsoft Azure Kubernetes 安全漏洞 — Azure Kubernetes Service | 9.0 | Critical | 2024-03-12 |
| CVE-2024-1303 | s::can moni::tools 路径遍历漏洞 — Monitool | 6.5 | Medium | 2024-03-12 |
| CVE-2023-47221 | QNAP Systems Photo Station 路径遍历漏洞 — Photo Station | 5.5 | Medium | 2024-03-08 |
| CVE-2024-0818 | PaddlePaddle 路径遍历漏洞 — paddlepaddle/paddle | 9.1AI | CriticalAI | 2024-03-07 |
| CVE-2024-1142 | Sonatype IQ Server 安全漏洞 — IQ Server | 5.4 | Medium | 2024-03-06 |
| CVE-2023-38366 | IBM Content Navigator 路径遍历漏洞 — Filenet Content Manager | 5.3 | Medium | 2024-03-01 |
| CVE-2024-2045 | Session 路径遍历漏洞 — Session | 5.5 | Medium | 2024-02-29 |
| CVE-2024-23946 | Apache OFBiz 代码问题漏洞 — Apache OFBiz | 9.1 | - | 2024-02-28 |
| CVE-2024-25065 | Apache OFBiz 安全漏洞 — Apache OFBiz | 9.1 | - | 2024-02-28 |
| CVE-2024-0763 | AnythingLLM 输入验证错误漏洞 — mintplex-labs/anything-llm | 8.1 | - | 2024-02-27 |
| CVE-2024-27081 | ESPHome 安全漏洞 — esphome | 7.2 | High | 2024-02-26 |
| CVE-2024-1165 | WordPress Plugin Brizy – Page Builder 安全漏洞 — Brizy – Page Builder | 4.3 | Medium | 2024-02-24 |
| CVE-2024-27318 | Open Neural Network Exchange 安全漏洞 — onnx | 7.5 | High | 2024-02-23 |
| CVE-2024-26150 | Backstage 安全漏洞 — backstage | 8.7 | High | 2024-02-23 |
| CVE-2023-24416 | WordPress Plugin All In One Favicon 路径遍历漏洞 — All In One Favicon | 6.8 | Medium | 2024-02-23 |
| CVE-2024-1704 | CRMEB 路径遍历漏洞 — CRMEB | 5.5 | Medium | 2024-02-21 |
| CVE-2024-1708 | ConnectWise ScreenConnect 安全漏洞 — ScreenConnect | 8.4 | High | 2024-02-21 |
| CVE-2024-26129 | PrestaShop 路径遍历漏洞 — PrestaShop | 5.8 | Medium | 2024-02-19 |
| CVE-2024-25123 | Mission Support System 安全漏洞 — MSS | 7.3 | High | 2024-02-15 |
| CVE-2024-23477 | SolarWinds Access Rights Manager 路径遍历漏洞 — Access Rights Manager | 7.9 | High | 2024-02-15 |
| CVE-2024-23476 | SolarWinds Access Rights Manager 路径遍历漏洞 — Access Rights Manager | 9.6 | Critical | 2024-02-15 |
| CVE-2024-23479 | SolarWinds Access Rights Manager 路径遍历漏洞 — Access Rights Manager | 9.6 | Critical | 2024-02-15 |
| CVE-2024-26261 | HGiga OAKlouds 路径遍历漏洞 — OAKlouds | 9.8 | Critical | 2024-02-15 |
| CVE-2024-25620 | Helm 路径遍历漏洞 — helm | 6.4 | Medium | 2024-02-14 |
| CVE-2024-23607 | F5 F5OS 安全漏洞 — F5OS - Appliance | 5.5 | Medium | 2024-02-14 |
| CVE-2023-5123 | Grafana 安全漏洞 — grafana-json-datasource | 8.0 | High | 2024-02-14 |
| CVE-2024-25125 | Digdag 路径遍历漏洞 — digdag | 5.3 | Medium | 2024-02-14 |
| CVE-2024-1485 | registry-support 安全漏洞 | 8.0 | High | 2024-02-13 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3717 条 CVE 漏洞。