CWE-350 不恰当地信任反向DNS 类弱点 14 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-350 属于依赖不可信数据源的安全漏洞。攻击者通过伪造 DNS 响应或劫持 DNS 服务器,将恶意 IP 映射为可信域名,从而绕过身份验证或访问控制。由于 DNS 记录易被篡改且难以验证真实性,仅凭反向解析结果进行安全决策存在巨大风险。开发者应避免依赖反向 DNS 进行关键安全判断,转而采用证书验证、IP 白名单或多因素认证等更可靠的机制来确保通信双方的真实身份。
struct hostent *hp;struct in_addr myaddr; char* tHost = "trustme.example.com"; myaddr.s_addr=inet_addr(ip_addr_string); hp = gethostbyaddr((char *) &myaddr, sizeof(struct in_addr), AF_INET); if (hp && !strncmp(hp->h_name, tHost, sizeof(tHost))) { trusted = true; } else { trusted = false; }String ip = request.getRemoteAddr(); InetAddress addr = InetAddress.getByName(ip); if (addr.getCanonicalHostName().endsWith("trustme.com")) { trusted = true; }sd = socket(AF_INET, SOCK_DGRAM, 0); serv.sin_family = AF_INET; serv.sin_addr.s_addr = htonl(INADDR_ANY); servr.sin_port = htons(1008); bind(sd, (struct sockaddr *) & serv, sizeof(serv)); while (1) { memset(msg, 0x0, MAX_MSG); clilen = sizeof(cli); h=gethostbyname(inet_ntoa(cliAddr.sin_addr)); if (h->h_name==...) n = recvfrom(sd, msg, MAX_MSG, 0, (struct sockaddr *) & cli, &clilen); }while(true) { DatagramPacket rp=new DatagramPacket(rData,rData.length); outSock.receive(rp); String in = new String(p.getData(),0, rp.getLength()); InetAddress IPAddress = rp.getAddress(); int port = rp.getPort(); if ((rp.getHostName()==...) & (in==...)) { out = secret.getBytes(); DatagramPacket sp =new DatagramPacket(out,out.length, IPAddress, port); outSock.send(sp); } }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-6874 | Copilot API Proxy 安全漏洞 — copilot-api | 4.3 | Medium | 2026-04-22 |
| CVE-2026-24281 | Apache Zookeeper 安全漏洞 — Apache ZooKeeper | 7.4 | - | 2026-03-07 |
| CVE-2026-28271 | Kiteworks 代码问题漏洞 — security-advisories | 6.5 | Medium | 2026-02-27 |
| CVE-2026-1490 | WordPress plugin Spam protection, Anti-Spam, FireWall by CleanTalk 安全漏洞 — Spam protection, Honeypot, Anti-Spam by CleanTalk | 9.8 | Critical | 2026-02-15 |
| CVE-2025-59956 | AgentAPI 安全漏洞 — agentapi | 6.5 | Medium | 2025-09-29 |
| CVE-2025-59163 | SafeDep 安全漏洞 — vet | 4.3AI | MediumAI | 2025-09-29 |
| CVE-2024-53275 | HomeGallery 安全漏洞 — home-gallery | 8.1 | - | 2024-12-23 |
| CVE-2024-42364 | Homepage 安全漏洞 — homepage | 6.5 | Medium | 2024-08-23 |
| CVE-2022-22364 | IBM Cognos Controller 安全漏洞 — Cognos Controller | 5.3 | Medium | 2024-05-03 |
| CVE-2021-34561 | Pepperl Fuchs WirelessHART-Gateway安全漏洞 — WHA-GW-F2D2-0-AS- Z2-ETH | 7.5 | High | 2021-08-31 |
| CVE-2021-22884 | Nodejs 安全漏洞 — Node | 8.1 | - | 2021-03-03 |
| CVE-2020-11091 | Weaveworks Weave Net 安全漏洞 — Weave | 5.8 | Medium | 2020-06-03 |
| CVE-2018-7160 | Joyent Node.js inspector 安全漏洞 — Node.js | 8.8 | - | 2018-05-17 |
| CVE-2017-0902 | RubyGems 安全漏洞 — RubyGems | 8.1 | - | 2017-08-31 |
CWE-350(不恰当地信任反向DNS) 是常见的弱点类别,本平台收录该类弱点关联的 14 条 CVE 漏洞。