CVEbaza.plSłownik CWECWE-351
Common Weakness Enumeration

CWE-351

Insufficient Type Distinction

Kategoria: BaseCVE: 15
Opis

Produkt nie rozróżnia prawidłowo między różnymi typami elementów w sposób, który prowadzi do niezabezpieczonego zachowania. Brak odpowiedniej distinkcji typów może umożliwić atakującemu obejście kontroli bezpieczeństwa lub zamanipulowanie danymi.

Description (EN)

The product does not properly distinguish between different types of elements in a way that leads to insecure behavior.

Podatności CVE z CWE-351 (15)
9.3
CVSS
CRITICAL
CVE-2025-30510

Podatność w portalu Growatt Cloud Portal umożliwia atakującemu przesłanie dowolnego pliku w miejscu przeznaczonym na obraz instalacji fotowoltaicznej. Ze względu na brak walidacji przesyłanego pliku i krytyczny poziom oceny CVSS (9.3), podatność stwarza poważne ryzyko dla bezpieczeństwa systemu.

pub. 2025-04-15
8.8
CVSS
HIGH
CVE-2025-31951

HCL BigFix RunBookAI is affected by a Unvalidated Command Input / Potential Command Smuggling vulnerability. A flaw in a component's input handling was identified that could permit unauthorized command execution.

pub. 2026-05-06
8.7
CVSS
HIGH
CVE-2025-54412

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain a inconsistency in the OperatorFuncNode which can be exploited to hide the execution of untrusted operator methods. This can then be used in a code reuse attack to invoke seemingly safe functions and escalate to arbitrary code execution with minimal and misleading trusted types. This is fixed in version 0.12.0.

pub. 2025-07-26
8.7
CVSS
HIGH
CVE-2025-54413

skops is a Python library which helps users share and ship their scikit-learn based models. Versions 0.11.0 and below contain an inconsistency in MethodNode, which can be exploited to access unexpected object fields through dot notation. This can be used to achieve arbitrary code execution at load time. While this issue may seem similar to GHSA-m7f4-hrc6-fwg3, it is actually more severe, as it relies on fewer assumptions about trusted types. This is fixed in version 12.0.0.

pub. 2025-07-26
7.8
CVSS
HIGH
CVE-2023-38831

RARLAB WinRAR before 6.23 allows attackers to execute arbitrary code when a user attempts to view a benign file within a ZIP archive. The issue occurs because a ZIP archive may include a benign file (such as an ordinary .JPG file) and also a folder that has the same name as the benign file, and the contents of the folder (which may include executable content) are processed during an attempt to access only the benign file. This was exploited in the wild in April through October 2023.

pub. 2023-08-23🚩 CISA KEV⚡ EXPLOIT
7.5
CVSS
HIGH
CVE-2022-1642

A program using swift-corelibs-foundation is vulnerable to a denial of service attack caused by a potentially malicious source producing a JSON document containing a type mismatch. This vulnerability is caused by the interaction between a deserialization mechanism offered by the Swift standard library, the Codable protocol; and the JSONDecoder class offered by swift-corelibs-foundation, which can deserialize types that adopt the Codable protocol based on the content of a provided JSON document. When a type that adopts Codable requests the initialization of a field with an integer value, the JSONDecoder class uses a type-erased container with different accessor methods to attempt and coerce a corresponding JSON value and produce an integer. In the case the JSON value was a numeric literal with a floating-point portion, JSONDecoder used different type-eraser methods during validation than it did during the final casting of the value. The checked casting produces a deterministic crash due to this mismatch. The JSONDecoder class is often wrapped by popular Swift-based web frameworks to parse the body of HTTP requests and perform basic type validation. This makes the attack low-effort: sending a specifically crafted JSON document during a request to these endpoints will cause them to crash. The attack does not have any confidentiality or integrity risks in and of itself; the crash is produced deterministically by an abort function that ensures that execution does not continue in the face of this violation of assumptions. However, unexpected crashes can lead to violations of invariants in services, so it's possible that this attack can be used to trigger error conditions that escalate the risk. Producing a denial of service may also be the goal of an attacker in itself. This issue is solved in Swift 5.6.2 for Linux and Windows. This issue was solved by ensuring that the same methods are invoked both when validating and during casting, so that no type mismatch occurs. Swift for Linux and Windows versions are not ABI-interchangeable. To upgrade a service, its owner must update to this version of the Swift toolchain, then recompile and redeploy their software. The new version of Swift includes an updated swift-corelibs-foundation package. Versions of Swift running on Darwin-based operating systems are not affected.

pub. 2022-06-16
7.3
CVSS
HIGH
CVE-2023-2866

If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.

pub. 2023-06-07
6.6
CVSS
MEDIUM
CVE-2025-65960

Contao jest open source'owym CMS. W wersjach od 4.0.0 do przed 4.13.57, przed 5.3.42 i przed 5.6.5, użytkownicy backendu mający precyzyjną kontrolę nad zawartością zamknięć szablonów mogą wykonywać arbitralne funkcje PHP, które nie mają wymaganych parametrów. Problem został naprawiony w wersjach 4.13.57, 5.3.42 i 5.6.5. Obejściem jest ręczne patchowanie metody Contao\Template::once().

pub. 2025-11-25
6.3
CVSS
MEDIUM
CVE-2026-15305

Użytkownicy mogli przesyłać pliki z dowolnymi typami MIME do formularzy przy użyciu elementów FileUpload lub ImageUpload ze skonfigurowanymi allowedMimeTypes. Ograniczenie nie było egzekwowane po stronie serwera, ponieważ MimeTypeValidator został zarejestrowany podczas budowania formularza przed zastosowaniem właściwości konkretnej definicji formularza, co spowodowało, że validator nigdy nie został dodany do pipeline'u przetwarzania. Problem dotyczy TYPO3 CMS w wersjach 14.2.0-14.3.4.

pub. 2026-07-14
6.3
CVSS
MEDIUM
CVE-2020-10134

Pairing in Bluetooth® Core v5.2 and earlier may permit an unauthenticated attacker to acquire credentials with two pairing devices via adjacent access when the unauthenticated user initiates different pairing methods in each peer device and an end-user erroneously completes both pairing procedures with the MITM using the confirmation number of one peer as the passkey of the other. An adjacent, unauthenticated attacker could be able to initiate any Bluetooth operation on either attacked device exposed by the enabled Bluetooth profiles. This exposure may be limited when the user must authorize certain access explicitly, but so long as a user assumes that it is the intended remote device requesting permissions, device-local protections may be weakened.

pub. 2020-05-19
5.9
CVSS
MEDIUM
CVE-2024-4769

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

pub. 2024-05-14
5.4
CVSS
MEDIUM
CVE-2025-47939

TYPO3 is an open source, PHP based web content management system. By design, the file management module in TYPO3’s backend user interface has historically allowed the upload of any file type, with the exception of those that are directly executable in a web server context. This lack of restriction means it is possible to upload files that may be considered potentially harmful, such as executable binaries (e.g., `.exe` files), or files with inconsistent file extensions and MIME types (for example, a file incorrectly named with a `.png` extension but actually carrying the MIME type `application/zip`) starting in version 9.0.0 and prior to versions 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, and 13.4.12 LTS. Although such files are not directly executable through the web server, their presence can introduce indirect risks. For example, third-party services such as antivirus scanners or malware detection systems might flag or block access to the website for end users if suspicious files are found. This could negatively affect the availability or reputation of the site. Users should update to TYPO3 version 9.5.51 ELTS, 10.4.50 ELTS, 11.5.44 ELTS, 12.4.31 LTS, or 13.4.12 LTS to fix the problem.

pub. 2025-05-20
4.3
CVSS
MEDIUM
CVE-2024-45676

IBM Cognos Controller 11.0.0 and 11.0.1 could allow an authenticated user to upload insecure files, due to insufficient file type distinction.

pub. 2024-12-03
2.6
CVSS
LOW
CVE-2025-32035

DNN (dawniej DotNetNuke) to open-source'owa platforma zarządzania treścią (CMS) w ekosystemie Microsoft. W wersjach wcześniejszych niż 9.13.2, podczas przesyłania plików (np. zasobów), system sprawdzał tylko rozszerzenie pliku, ale nie weryfikował jego faktyczną zawartość. Umożliwiało to przesłanie na przykład pliku wykonywalnego przebrańskiego za plik .jpg, który mógł zostać wykonany przez inną lukę bezpieczeństwa. Podatność została naprawiona w wersji 9.13.2.

pub. 2025-04-08
2.3
CVSS
LOW
CVE-2026-41341

OpenClaw przed wersją 2026.3.31 zawiera błąd logiki w routingu interakcji komponentów Discord, który nieprawidłowo klasyfikuje grupowe wiadomości bezpośrednie jako wiadomości bezpośrednie w pliku extensions/discord/src/monitor/agent-components-helpers.ts. Atakujący mogą wykorzystać tę błędną klasyfikację do obejścia egzekwowania polityki grupowych DM lub wyzwolenia nieprawidłowej obsługi sesji.

pub. 2026-04-23
Informacje
ID: CWE-351
Typ: Base
Podatności: 15
MITRE CWE ↗
← Słownik CWE