CWE-502 可信数据的反序列化 类弱点 1702 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2024-23513 | WordPress Plugin PropertyHive 代码问题漏洞 — PropertyHive | 8.7 | High | 2024-02-12 |
| CVE-2024-24796 | WordPress Plugin WpEvently 代码问题漏洞 — Event Manager and Tickets Selling Plugin for WooCommerce – WpEvently – WordPress Plugin | 8.2 | High | 2024-02-12 |
| CVE-2024-24797 | WordPress Plugin ERE Recently Viewed 代码问题漏洞 — ERE Recently Viewed – Essential Real Estate Add-On | 9.8 | Critical | 2024-02-12 |
| CVE-2024-24926 | WordPress Plugin Brooklyn 代码问题漏洞 — Brooklyn | Creative Multi-Purpose Responsive WordPress Theme | 7.5 | High | 2024-02-12 |
| CVE-2024-25100 | WordPress Plugin Coupon Referral Program 代码问题漏洞 — Coupon Referral Program | 10.0 | Critical | 2024-02-12 |
| CVE-2024-1432 | DeepFaceLab 代码问题漏洞 — DeepFaceLab | 5.0 | Medium | 2024-02-11 |
| CVE-2024-1353 | PHPEMS 代码问题漏洞 — PHPEMS | 6.3 | Medium | 2024-02-09 |
| CVE-2024-24590 | Allegro 代码问题漏洞 — ClearML | 8.0 | High | 2024-02-06 |
| CVE-2024-0668 | WordPress plugin Advanced Database Cleaner 安全漏洞 — Advanced Database Cleaner – Optimize & Clean Database to Speed Up Site Performance | 6.6 | Medium | 2024-02-05 |
| CVE-2023-6933 | WordPress plugin Better Search Replace 安全漏洞 — Better Search Replace | 8.8 | High | 2024-02-05 |
| CVE-2024-1225 | Qibosoft QiboCMS 代码问题漏洞 — QiboCMS X1 | 7.3 | High | 2024-02-05 |
| CVE-2024-1198 | openBI 代码问题漏洞 — openBI | 6.3 | Medium | 2024-02-02 |
| CVE-2024-22320 | IBM Operational Decision Manager 代码问题漏洞 — Operational Decision Manager | 9.8 | Critical | 2024-02-02 |
| CVE-2024-23328 | DataEase 安全漏洞 — dataease | 9.1 | Critical | 2024-02-01 |
| CVE-2024-1032 | openBI 代码问题漏洞 — openBI | 7.3 | High | 2024-01-30 |
| CVE-2024-0960 | ai-flow 代码问题漏洞 — ai-flow | 5.0 | Medium | 2024-01-27 |
| CVE-2024-0959 | StanfordVL GibsonEnv 代码问题漏洞 — GibsonEnv | 5.0 | Medium | 2024-01-27 |
| CVE-2024-0937 | van_der_Schaar LAB synthcity 代码问题漏洞 — synthcity | 6.3 | Medium | 2024-01-26 |
| CVE-2024-20253 | Cisco Unified Communications Products 安全漏洞 — Cisco Unified Contact Center Enterprise | 9.9 | Critical | 2024-01-26 |
| CVE-2024-0936 | TemporAI 代码问题漏洞 — TemporAI | 6.3 | Medium | 2024-01-26 |
| CVE-2023-50943 | Apache Airflow 代码问题漏洞 — Apache Airflow | 8.2 | - | 2024-01-24 |
| CVE-2024-22284 | WordPress plugin Asgaros Forum 代码问题漏洞 — Asgaros Forum | 8.7 | High | 2024-01-24 |
| CVE-2024-22309 | WordPress plugin ChatBot with AI 代码问题漏洞 — ChatBot with AI | 8.7 | High | 2024-01-24 |
| CVE-2024-23636 | SOFARPC 代码问题漏洞 — sofa-rpc | 9.8 | Critical | 2024-01-23 |
| CVE-2024-0739 | Leadshop 代码问题漏洞 — Leadshop | 7.3 | High | 2024-01-19 |
| CVE-2022-45845 | WordPress plugin Smart Slider 3 代码问题漏洞 — Smart Slider 3 | 4.3 | Medium | 2024-01-19 |
| CVE-2022-45083 | WordPress plugin ProfilePress 代码问题漏洞 — Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress | 6.6 | Medium | 2024-01-19 |
| CVE-2024-0654 | DeepFaceLab 代码问题漏洞 — DeepFaceLab | 5.3 | Medium | 2024-01-18 |
| CVE-2024-0603 | ZhiCms 代码问题漏洞 — ZhiCms | 7.3 | High | 2024-01-16 |
| CVE-2023-7032 | Schneider Electric Easergy Studio 代码问题漏洞 — Easergy Studio | 7.8 | High | 2024-01-09 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 1702 条 CVE 漏洞。