CWE-939 自定义URL方案处理程序中的授权不正确 类弱点 12 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-939 指应用在处理自定义 URL Scheme 时缺乏适当的授权控制。攻击者常通过构造恶意链接或诱导点击,利用未受限制的 Scheme 调用机制,触发目标应用执行非预期操作或访问敏感数据。开发者应实施严格的来源验证与权限检查,确保仅可信实体能调用特定 Handler,从而防止未授权访问并保障应用间通信的安全性。
NSString *stringURL = @"appscheme://replaceFileText?file=incomingMessage.txt&text=hello"; NSURL *url = [NSURL URLWithString:stringURL]; [[UIApplication sharedApplication] openURL:url];- (BOOL)application:(UIApplication *)application handleOpenURL:(NSURL *)url { if (!url) { return NO; } NSString *action = [url host]; if([action isEqualToString: @"replaceFileText"]) { NSDictionary *dict = [self parseQueryStringExampleFunction:[url query]]; //this function will write contents to a specified file FileObject *objectFile = [self writeToFile:[dict objectForKey: @"file"] withText:[dict objectForKey: @"text"]]; } return YES; }// Android @Override public boolean shouldOverrideUrlLoading(WebView view, String url){ if (url.substring(0,14).equalsIgnoreCase("examplescheme:")){ if(url.substring(14,25).equalsIgnoreCase("getUserInfo")){ writeDataToView(view, UserData); return false; } else{ return true; } } }// iOS -(BOOL) webView:(UIWebView *)exWebView shouldStartLoadWithRequest:(NSURLRequest *)exRequest navigationType:(UIWebViewNavigationType)exNavigationType { NSURL *URL = [exRequest URL]; if ([[URL scheme] isEqualToString:@"exampleScheme"]) { NSString *functionString = [URL resourceSpecifier]; if ([functionString hasPrefix:@"specialFunction"]) { // Make data available back in webview. UIWebView *webView = [self writeDataToView:[URL query]]; } return NO; } return YES; }| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2026-35394 | Mobile Next 安全漏洞 — mobile-mcp | 8.3 | High | 2026-04-06 |
| CVE-2026-33335 | Vikunja 安全漏洞 — vikunja | 6.1 | - | 2026-03-24 |
| CVE-2026-26123 | Microsoft Authenticator 安全漏洞 — Microsoft Authenticator for Android | 5.5 | Medium | 2026-03-10 |
| CVE-2026-1046 | Mattermost Desktop App 安全漏洞 — Mattermost | 7.6 | High | 2026-02-16 |
| CVE-2025-67739 | JetBrains TeamCity 安全漏洞 — TeamCity | 3.1 | Low | 2025-12-11 |
| CVE-2025-41408 | LY Yahoo! Shopping App 安全漏洞 — "Yahoo! Shopping" App for Android | 6.1AI | MediumAI | 2025-09-05 |
| CVE-2024-54125 | Shonen Jump+ 安全漏洞 — "Shonen Jump+" App for Android | 6.1 | - | 2024-12-17 |
| CVE-2024-54014 | Skylark Holdings Skylark App 安全漏洞 — 'Skylark' App for Android | 6.5AI | MediumAI | 2024-12-05 |
| CVE-2024-33606 | MicroDicom DICOM Viewer 安全漏洞 — DICOM Viewer | 8.8 | High | 2024-06-11 |
| CVE-2023-43582 | Zoom Client 授权问题漏洞 — Zoom Clients | 5.5 | Medium | 2023-11-14 |
| CVE-2022-20736 | Cisco AppDynamics Controller 安全漏洞 — Cisco AppDynamics | 5.3 | Medium | 2022-06-15 |
| CVE-2020-11000 | GreenBrowser 安全漏洞 — GreenBrowser | 5.7 | Medium | 2020-04-08 |
CWE-939(自定义URL方案处理程序中的授权不正确) 是常见的弱点类别,本平台收录该类弱点关联的 12 条 CVE 漏洞。