CWE-22 对路径名的限制不恰当(路径遍历) 类弱点 3669 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-22 属于路径遍历漏洞,指程序未正确过滤外部输入中的特殊字符,导致构造的文件路径突破受限目录限制。攻击者常利用“../”等序列访问系统敏感文件,窃取数据或执行恶意操作。开发者应严格校验输入,使用白名单机制限制合法字符,并采用绝对路径或规范化处理,确保最终解析路径始终位于预期目录内,从而有效防御此类风险。
my $dataPath = "/users/cwe/profiles"; my $username = param("user"); my $profilePath = $dataPath . "/" . $username; open(my $fh, "<", $profilePath) || ExitError("profile read error: $profilePath"); print "<ul>\n"; while (<$fh>) { print "<li>$_</li>\n"; } print "</ul>\n";../../../etc/passwdString filename = System.getProperty("com.domain.application.dictionaryFile"); File dictionaryFile = new File(filename);| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-23365 | QNAP Systems Music Station 路径遍历漏洞 — Music Station | 7.7 | High | 2023-10-06 |
| CVE-2023-43070 | Dell SmartFabric Storage Software 路径遍历漏洞 — Dell SmartFabric Storage Software | 6.3 | Medium | 2023-10-05 |
| CVE-2023-5399 | Schneider Electric C-Bus Toolkit 路径遍历漏洞 — C-Bus Toolkit | 9.8 | Critical | 2023-10-04 |
| CVE-2023-26152 | static-server 路径遍历漏洞 — static-server | 7.5 | High | 2023-10-03 |
| CVE-2023-5327 | SATO America CL4NX 路径遍历漏洞 — CL4NX-J Plus | 3.5 | Low | 2023-10-01 |
| CVE-2023-5257 | WhiteHSBG JNDIExploit 路径遍历漏洞 — JNDIExploit | 3.5 | Low | 2023-09-29 |
| CVE-2023-43662 | ShokoServer 路径遍历漏洞 — ShokoServer | 8.6 | High | 2023-09-28 |
| CVE-2023-43044 | IBM License Metric Tool 路径遍历漏洞 — License Metric Tool | 5.3 | Medium | 2023-09-28 |
| CVE-2023-40026 | ArgoCD 路径遍历漏洞 — argo-cd | 5.0 | Medium | 2023-09-27 |
| CVE-2023-42657 | WS_FTP Server 路径遍历漏洞 — WS_FTP Server | 9.9 | Critical | 2023-09-27 |
| CVE-2023-42487 | Soundminer SM server 路径遍历漏洞 — Soundminer | 7.5 | High | 2023-09-27 |
| CVE-2023-42462 | GLPI 代码问题漏洞 — glpi | 7.7 | High | 2023-09-26 |
| CVE-2023-41888 | GLPI 路径遍历漏洞 — glpi | 5.3 | Medium | 2023-09-26 |
| CVE-2023-42819 | Jumpserver 路径遍历漏洞 — jumpserver | 8.9 | High | 2023-09-26 |
| CVE-2023-2315 | OpenCart 路径遍历漏洞 — Opencart | 8.1 | High | 2023-09-26 |
| CVE-2022-4244 | codehaus-plexus 路径遍历漏洞 — RHINT Camel-K-1.10.1 | 7.5 | High | 2023-09-25 |
| CVE-2023-41302 | Huawei HarmonyOS 安全漏洞 — HarmonyOS | - | - | 2023-09-25 |
| CVE-2023-39407 | Huawei HarmonyOS 路径遍历漏洞 — HarmonyOS | 9.1 | - | 2023-09-25 |
| CVE-2023-5142 | H3C ER Series 路径遍历漏洞 — GR-1100-P | 3.7 | Low | 2023-09-24 |
| CVE-2023-4760 | Eclipse RAP 路径遍历漏洞 — Eclipse RAP | 7.6 | High | 2023-09-21 |
| CVE-2023-4152 | Frauscher Sensortechnik FDS101 路径遍历漏洞 — FDS101 for FAdC/FAdCi | 7.5 | High | 2023-09-21 |
| CVE-2022-45447 | Prestashop 路径遍历漏洞 — M4 PDF plugin | 6.5 | Medium | 2023-09-20 |
| CVE-2023-38256 | Dover Fueling Solutions MAGLINK LX Console 路径遍历漏洞 — MAGLINK LX Web Console Configuration | 6.8 | Medium | 2023-09-11 |
| CVE-2022-33164 | IBM Security Directory Server 路径遍历漏洞 — Security Directory Integrator | 8.7 | High | 2023-09-08 |
| CVE-2023-4782 | HashiCorp Terraform 路径遍历漏洞 — Terraform | 6.3 | Medium | 2023-09-08 |
| CVE-2021-35980 | Adobe Acrobat 路径遍历漏洞 — Acrobat Reader | 7.8 | High | 2023-09-06 |
| CVE-2021-28644 | Adobe Acrobat 路径遍历漏洞 — Acrobat Reader | 7.8 | High | 2023-09-06 |
| CVE-2023-4748 | Yonyou UFIDA-NC 路径遍历漏洞 — UFIDA-NC | 6.3 | Medium | 2023-09-05 |
| CVE-2023-41057 | Hyper Bump It 路径遍历漏洞 — hyper-bump-it | 5.5 | Medium | 2023-09-04 |
| CVE-2023-4616 | LG LED Assistant 路径遍历漏洞 — LG-LED Assistant | 7.5 | High | 2023-09-04 |
CWE-22(对路径名的限制不恰当(路径遍历)) 是常见的弱点类别,本平台收录该类弱点关联的 3669 条 CVE 漏洞。