CWE-502 可信数据的反序列化 类弱点 1698 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-28859 | Symfony 安全漏洞 — symfony1 | 5.0 | Medium | 2024-03-15 |
| CVE-2024-1950 | WordPress Plugin Product Carousel Slider & Grid Ultimate for WooCommerce 安全漏洞 — Product Carousel Slider & Grid Ultimate for WooCommerce | 7.5 | High | 2024-03-13 |
| CVE-2024-1951 | WordPress Plugin Logo Showcase Ultimate 安全漏洞 — Logo Showcase Ultimate – Logo Carousel, Logo Slider & Logo Grid | 7.5 | High | 2024-03-13 |
| CVE-2024-2006 | WordPress Plugin Post Grid, Slider & Carousel Ultimate 安全漏洞 — Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget | 8.8 | High | 2024-03-13 |
| CVE-2024-1772 | WordPress Plugin Play.ht 安全漏洞 — Play.ht – Make Your Blog Posts Accessible With Text to Speech Audio | 8.8 | High | 2024-03-13 |
| CVE-2024-1773 | WordPress plugin PDF Invoices and Packing Slips For WooCommerce 安全漏洞 — PDF Invoices and Packing Slips For WooCommerce | 8.8 | High | 2024-03-07 |
| CVE-2024-28213 | nGrinder 安全漏洞 — nGrinder | 9.8AI | CriticalAI | 2024-03-07 |
| CVE-2024-28212 | nGrinder 安全漏洞 — nGrinder | 9.8AI | CriticalAI | 2024-03-07 |
| CVE-2024-28211 | nGrinder 安全漏洞 — nGrinder | 9.8AI | CriticalAI | 2024-03-07 |
| CVE-2024-26580 | Apache InLong 代码问题漏洞 — Apache InLong | 9.1AI | CriticalAI | 2024-03-06 |
| CVE-2024-2054 | Artica Proxy 代码问题漏洞 — Artica Proxy | 9.8 | - | 2024-03-05 |
| CVE-2024-0825 | WordPress Plugin Vimeography 安全漏洞 — Vimeography: Vimeo Video Gallery WordPress Plugin | 8.8 | High | 2024-03-05 |
| CVE-2024-1731 | WordPress Plugin Auto Refresh Single Page 安全漏洞 — Auto Refresh Single Page | 8.8 | High | 2024-03-05 |
| CVE-2024-0692 | SolarWinds Security Event Manager 代码问题漏洞 — Security Event Manager | 8.8 | High | 2024-03-01 |
| CVE-2024-1859 | WordPress Plugin Slider Responsive Slideshow 安全漏洞 — Responsive Slideshow | 8.8 | High | 2024-03-01 |
| CVE-2023-51518 | Apache James 代码问题漏洞 — Apache James server | 7.8 | - | 2024-02-27 |
| CVE-2024-1750 | TemmokuMVC 代码问题漏洞 — TemmokuMVC | 5.6 | Medium | 2024-02-22 |
| CVE-2024-1748 | van_der_Schaar LAB AutoPrognosis 代码问题漏洞 — AutoPrognosis | 5.0 | Medium | 2024-02-22 |
| CVE-2023-51389 | Hertzbeat 安全漏洞 — hertzbeat | 9.8 | Critical | 2024-02-22 |
| CVE-2024-23114 | Apache Camel 代码问题漏洞 — Apache Camel | 9.8 | - | 2024-02-20 |
| CVE-2024-22369 | Apache Camel 代码问题漏洞 — Apache Camel | 9.8 | - | 2024-02-20 |
| CVE-2024-1651 | Torrentpier 代码问题漏洞 — Torrentpier | 10.0 | Critical | 2024-02-19 |
| CVE-2023-40057 | SolarWinds Access Rights Manager 代码问题漏洞 — Access Rights Manager | 9.0 | Critical | 2024-02-15 |
| CVE-2024-23478 | SolarWinds Access Rights Manager 代码问题漏洞 — Access Rights Manager | 8.0 | High | 2024-02-15 |
| CVE-2023-46615 | WordPress Plugin KD Coming Soon 代码问题漏洞 — KD Coming Soon | 5.4 | Medium | 2024-02-12 |
| CVE-2024-23512 | WordPress Plugin ProductX 代码问题漏洞 — ProductX – WooCommerce Builder & Gutenberg WooCommerce Blocks | 8.7 | High | 2024-02-12 |
| CVE-2024-23513 | WordPress Plugin PropertyHive 代码问题漏洞 — PropertyHive | 8.7 | High | 2024-02-12 |
| CVE-2024-24796 | WordPress Plugin WpEvently 代码问题漏洞 — Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | 8.2 | High | 2024-02-12 |
| CVE-2024-24797 | WordPress Plugin ERE Recently Viewed 代码问题漏洞 — ERE Recently Viewed – Essential Real Estate Add-On | 9.8 | Critical | 2024-02-12 |
| CVE-2024-24926 | WordPress Plugin Brooklyn 代码问题漏洞 — Brooklyn | Creative Multi-Purpose Responsive WordPress Theme | 7.5 | High | 2024-02-12 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 1698 条 CVE 漏洞。