CWE-502 可信数据的反序列化 类弱点 1854 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-502 指反序列化不可信数据漏洞,属于数据验证缺陷。攻击者通过构造恶意序列化对象,在系统反序列化时触发任意代码执行或拒绝服务。开发者应避免直接反序列化外部输入,改用 JSON 等安全格式,或实施严格的类白名单校验与完整性检查,确保反序列化过程仅处理预期类型,从而阻断恶意载荷执行。
try { File file = new File("object.obj"); ObjectInputStream in = new ObjectInputStream(new FileInputStream(file)); javax.swing.JButton button = (javax.swing.JButton) in.readObject(); in.close(); }private final void readObject(ObjectInputStream in) throws java.io.IOException { throw new java.io.IOException("Cannot be deserialized"); }try { class ExampleProtocol(protocol.Protocol): def dataReceived(self, data): # Code that would be here would parse the incoming data # After receiving headers, call confirmAuth() to authenticate def confirmAuth(self, headers): try: token = cPickle.loads(base64.b64decode(headers['AuthToken'])) if not check_hmac(token['signature'], token['data'], getSecretKey()): raise AuthFail self.secure_data = token['data'] except: raise AuthFail }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2021-21524 | Dell EMC Storage Resource Manager 代码问题漏洞 — Dell EMC Storage Monitoring and Reporting | 9.8 | - | 2021-04-12 |
| CVE-2021-24217 | WordPress 插件 代码问题漏洞 — Facebook for WordPress | 8.1 | - | 2021-04-12 |
| CVE-2021-1415 | 思科 Cisco 路由器 代码问题漏洞 — Cisco Small Business RV Series Router Firmware | 6.3 | Medium | 2021-04-08 |
| CVE-2021-1414 | 思科 Cisco 路由器 代码问题漏洞 — Cisco Small Business RV Series Router Firmware | 6.3 | Medium | 2021-04-08 |
| CVE-2021-1413 | 思科 Cisco 路由器 代码问题漏洞 — Cisco Small Business RV Series Router Firmware | 6.3 | Medium | 2021-04-08 |
| CVE-2021-27240 | solarwinds Patch Manager 代码问题漏洞 — Patch Manager | 7.8 | - | 2021-03-29 |
| CVE-2021-21349 | XStream 代码问题漏洞 — xstream | 6.1 | Medium | 2021-03-22 |
| CVE-2021-21342 | XStream 代码问题漏洞 — xstream | 5.3 | Medium | 2021-03-22 |
| CVE-2021-21371 | Alex Weber Tenable 代码问题漏洞 — integration-jira-cloud | 5.0 | Medium | 2021-03-10 |
| CVE-2021-22855 | Soar Cloud System HR 代码问题漏洞 — HR Portal | 9.8 | Critical | 2021-02-17 |
| CVE-2020-27868 | Qognify Ocularis 代码问题漏洞 — Ocularis | 9.8 | - | 2021-02-11 |
| CVE-2020-12525 | M&M Fdtcontainer 代码问题漏洞 — fdtCONTAINER Component | 7.3 | High | 2021-01-22 |
| CVE-2021-20190 | FasterXML jackson-databind 代码问题漏洞 — jackson-databind | 8.1 | - | 2021-01-19 |
| CVE-2020-11995 | Apache Dubbo 代码问题漏洞 — Apache Dubbo | 9.8 | - | 2021-01-11 |
| CVE-2020-17531 | Apache Tapestry 代码问题漏洞 — Apache Tapestry | 9.8 | - | 2020-12-08 |
| CVE-2020-26207 | Martinjw DatabaseSchemaViewer 代码问题漏洞 — dbschemareader | 8.0 | High | 2020-11-04 |
| CVE-2020-10721 | fabric8-maven-plugin 代码问题漏洞 — fabric8-maven-plugin | 7.8 | - | 2020-10-22 |
| CVE-2020-15244 | Adobe Magento 代码问题漏洞 — magento-lts | 8.0 | High | 2020-10-21 |
| CVE-2020-26867 | ARC Informatique PcVue 代码问题漏洞 — PcVue | 9.8 | Critical | 2020-10-12 |
| CVE-2020-7811 | Samsung Update 代码问题漏洞 — Samsung Update | 6.2 | Medium | 2020-10-12 |
| CVE-2020-15188 | SOY CMS 代码问题漏洞 — soycms | 10.0 | Critical | 2020-09-18 |
| CVE-2020-7532 | 施耐德 SCADAPack 代码问题漏洞 — SCADAPack x70 Security Administrator V1.2.0 and prior. | 7.8 | - | 2020-09-16 |
| CVE-2020-7528 | SCADAPack Remote Connect 代码问题漏洞 — SCADAPack 7x Remote Connect V3.6.3.574 and prior. | 7.8 | - | 2020-09-16 |
| CVE-2020-15172 | Red Discord Bot 代码问题漏洞 — FluffyCogs | 8.7 | High | 2020-09-15 |
| CVE-2020-15148 | Yii 代码问题漏洞 — yii2 | 8.9 | High | 2020-09-15 |
| CVE-2020-17405 | Senstar Symphony 代码执行漏洞 — Symphony | 8.8 | - | 2020-09-01 |
| CVE-2020-5413 | Pivotal Software Spring Integration 代码问题漏洞 — Spring Integration | 9.8 | - | 2020-07-31 |
| CVE-2019-11286 | VMware GemFire和Tanzu GemFire for VMs 代码问题漏洞 — VMware GemFire | 9.1 | - | 2020-07-31 |
| CVE-2020-10917 | NEC ESMPRO Manager 代码问题漏洞 — ESMPRO Manager | 9.8 | - | 2020-07-22 |
| CVE-2020-12007 | Mitsubishi Electric MC Works64和ICONICS GENESIS64 FrameWorX Server 代码问题漏洞 — MC Works64 | 9.8 | - | 2020-07-16 |
CWE-502(可信数据的反序列化) 是常见的弱点类别,本平台收录该类弱点关联的 1854 条 CVE 漏洞。