CWE-863 授权机制不正确 类弱点 1279 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-863属于授权检查缺陷,指系统在验证用户访问权限时未能正确执行检查逻辑。攻击者通常利用此漏洞,通过构造恶意请求或篡改参数,绕过权限控制以访问未授权资源或执行敏感操作。开发者应避免此问题,需确保在关键操作前严格验证用户身份与权限,采用最小权限原则,并实施集中式的授权管理,防止逻辑绕过或硬编码错误。
$role = $_COOKIES['role']; if (!$role) { $role = getRole('user'); if ($role) { // save the cookie to send out in future responses setcookie("role", $role, time()+60*60*2); } else{ ShowLoginScreen(); die("\n"); } } if ($role == 'Reader') { DisplayMedicalHistory($_POST['patient_ID']); } else{ die("You are not Authorized to view this record\n"); }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2023-22251 | Adobe Commerce 安全漏洞 — Magento Commerce | 4.3 | Medium | 2023-03-27 |
| CVE-2023-25017 | RIFARTEK IOT Wall 安全漏洞 — IOT Wall | 8.1 | High | 2023-03-27 |
| CVE-2023-25923 | IBM Security Guardium 安全漏洞 — Security Key Lifecycle Manager | 2.7 | Low | 2023-03-21 |
| CVE-2023-25924 | IBM Security Guardium 安全漏洞 — Security Key Lifecycle Manager | 5.4 | Medium | 2023-03-21 |
| CVE-2023-26484 | KubeVirt 安全漏洞 — kubevirt | 8.2 | High | 2023-03-15 |
| CVE-2022-39214 | Combodo iTop 安全漏洞 — iTop | 9.6 | Critical | 2023-03-14 |
| CVE-2023-24999 | HashiCorp Vault 安全漏洞 — Vault | 4.4 | Medium | 2023-03-10 |
| CVE-2023-27486 | xCAT 安全漏洞 — xcat-core | 8.1 | High | 2023-03-08 |
| CVE-2023-27485 | Feedbacksystem 安全漏洞 — feedbacksystem | 4.3 | Medium | 2023-03-07 |
| CVE-2023-26056 | XWiki Platform 安全漏洞 — xwiki-platform | 5.4 | Medium | 2023-03-02 |
| CVE-2023-23947 | ArgoCD 安全漏洞 — argo-cd | 9.1 | Critical | 2023-02-16 |
| CVE-2023-25173 | containerd 安全漏洞 — containerd | 5.3 | Medium | 2023-02-16 |
| CVE-2022-34397 | Dell EMC Unisphere for PowerMax 安全漏洞 — Unisphere for PowerMax | 6.9 | Medium | 2023-02-13 |
| CVE-2023-24829 | Apache IoTDB 安全漏洞 — Apache IoTDB Workbench | 8.8 | - | 2023-01-31 |
| CVE-2022-45435 | IdentityIQ 安全漏洞 — IdentityIQ | 6.8 | Medium | 2023-01-31 |
| CVE-2023-22610 | EcoStruxure Geo SCADA Expert 安全漏洞 — EcoStruxure Geo SCADA Expert 2019 - 2021 (formerly known as ClearSCADA) | 9.1 | Critical | 2023-01-31 |
| CVE-2023-22482 | Argo CD 安全漏洞 — argo-cd | 9.1 | Critical | 2023-01-25 |
| CVE-2023-22500 | GLPI 安全漏洞 — glpi | 7.5 | High | 2023-01-25 |
| CVE-2022-23739 | GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server | 7.8 | - | 2023-01-17 |
| CVE-2022-45353 | WordPress plugin Betheme theme 安全漏洞 — Betheme | 4.3 | Medium | 2023-01-14 |
| CVE-2023-0298 | firefly-iii 授权问题漏洞 — firefly-iii/firefly-iii | 7.1 | - | 2023-01-14 |
| CVE-2022-2155 | Hitachi Energy Lumada APM 安全漏洞 — Lumada APM | 5.7 | Medium | 2023-01-12 |
| CVE-2022-46258 | GitHub Enterprise Server 安全漏洞 — GitHub Enterprise Server | 6.5 | - | 2023-01-09 |
| CVE-2022-43438 | EasyTest 安全漏洞 — EasyTest | 8.8 | High | 2023-01-03 |
| CVE-2022-23553 | Alpine 安全漏洞 — alpine | 7.5 | High | 2022-12-28 |
| CVE-2020-36625 | destiny.gg chat 跨站请求伪造漏洞 — chat | 4.3 | Medium | 2022-12-22 |
| CVE-2022-3188 | Dataprobe iBoot-PDU 访问控制错误漏洞 — iBoot-PDU FW | 5.3 | Medium | 2022-12-21 |
| CVE-2020-36622 | Bienlein 跨站请求伪造漏洞 — bienlein | 4.3 | Medium | 2022-12-21 |
| CVE-2020-36623 | Bienlein 跨站请求伪造漏洞 — Pengu | 4.3 | Medium | 2022-12-21 |
| CVE-2021-4268 | phpRedisAdmin 跨站请求伪造漏洞 — phpRedisAdmin | 4.3 | Medium | 2022-12-21 |
CWE-863(授权机制不正确) 是常见的弱点类别,本平台收录该类弱点关联的 1279 条 CVE 漏洞。