CVEbaza.plSłownik CWECWE-436
Common Weakness Enumeration

CWE-436

Interpretation Conflict

Kategoria: ClassCVE: 154
Opis

Produkt A przetwarza dane wejściowe lub kroki inaczej niż Produkt B, co powoduje, że A wykonuje nieprawidłowe działania na podstawie swojej percepcji stanu B. Ta rozbieżność w interpretacji może prowadzić do niespójnego zachowania systemu.

Description (EN)

Product A handles inputs or steps differently than Product B, which causes A to perform incorrect actions based on its perception of B's state.

Podatności CVE z CWE-436 (154)
10.0
CVSS
CRITICAL
CVE-2023-24813

Podatność w bibliotece Dompdf (konwerter HTML do PDF) umożliwia atakującemu ominięcie mechanizmów ochrony i wywołanie dowolnych URL z dowolnymi protokołami poprzez spreparowany plik SVG. W środowiskach z PHP poniżej wersji 8.0.0 może to prowadzić do arbitrary unserialize, a w konsekwencji do RCE.

pub. 2023-02-07
9.8
CVSS
CRITICAL
CVE-2026-63030

Podatność w WordPress pozwala nieuwtelnionemu atakującemu na wykonanie dowolnego kodu (RCE) poprzez połączenie błędu route confusion w endpointach wsadowych REST API z podatnością SQL Injection w parametrze author__not_in mechanizmu WP_Query. Krytyczny poziom zagrożenia wynika z braku wymagań uwierzytelnienia i pełnego wpływu na poufność, integralność oraz dostępność systemu.

pub. 2026-07-17🚩 CISA KEV⚡ EXPLOIT
9.8
CVSS
CRITICAL
CVE-2021-45327

Gitea w wersjach przed 1.11.2 nieprawidłowo ufa metodom HTTP przekazywanym przez klienta przy odwołaniach do API administratora lub użytkownika. Podatność pozwala niezautoryzowanemu zdalnie atakującemu na wykonanie dowolnego kodu na serwerze.

pub. 2022-02-08
9.8
CVSS
CRITICAL
CVE-2020-10180

Silnik parsowania ESET pozwala na ominięcie wykrywania złośliwego oprogramowania za pomocą spreparowanego pola BZ2 Checksum w archiwum. Jest to podatność krytyczna, umożliwiająca przemycenie złośliwego kodu bez wykrycia przez produkt antywirusowy.

pub. 2020-03-05
9.8
CVSS
CRITICAL
CVE-2019-19589

Wtyczka Lever PDF Embedder 4.4 dla WordPress nie blokuje dystrybucji dokumentów PDF będących jednocześnie poprawnymi archiwami JAR (pliki polyglot). Może to umożliwić dystrybucję złośliwego oprogramowania ukrytego w pozornie niegroźnych plikach PDF.

pub. 2019-12-05
9.4
CVSS
CRITICAL
CVE-2026-57580

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK or EMAIL_LINK user-matching mode interprets an XML comment in a NameID differently from the identity provider's signed assertion. An attacker with an account on the source identity provider who can set the account's NameID can inject an XML comment that truncates the value used by authentik to the text before the comment while the signed assertion remains valid. A crafted NameID can therefore truncate to a victim's username or email and bind the attacker's external identity to the victim's existing account. This grants full takeover without the victim's password or the identity provider's private key, and the malicious link persists so later logins succeed without the comment. Sources using the default unique-identifier matching mode and authentik's outbound SAML Provider role are not affected. This issue is fixed in versions 2026.2.6 and 2026.5.5.

pub. 2026-08-18
9.3
CVSS
CRITICAL
CVE-2025-25291

Biblioteka ruby-saml w wersjach przed 1.12.4 i 1.18.0 zawiera krytyczną podatność umożliwiającą ominięcie uwierzytelnienia SAML SSO. Atakujący może podszyć się pod dowolnego użytkownika bez znajomości jego poświadczeń.

pub. 2025-03-12
9.3
CVSS
CRITICAL
CVE-2025-25292

W bibliotece ruby-saml wykryto krytyczną podatność umożliwiającą obejście uwierzytelnienia (authentication bypass) w mechanizmie SAML Single Sign-On. Atakujący bez żadnych uprawnień może przejąć tożsamość dowolnego użytkownika, w tym administratora.

pub. 2025-03-12
9.1
CVSS
CRITICAL
CVE-2026-14198

Podatność w bibliotece @fastify/middie (wersje 9.1.0–9.3.2) pozwala atakującemu ominąć middleware bezpieczeństwa poprzez wysłanie URL z zakodowanym slashem (%2F) w parametrze ścieżki. Może to skutkować nieautoryzowanym dostępem do chronionych zasobów, np. z pominięciem uwierzytelniania, autoryzacji lub rate limitingu.

pub. 2026-07-01
9.1
CVSS
CRITICAL
CVE-2026-41248

Funkcja createRouteMatcher w bibliotekach @clerk/nextjs, @clerk/nuxt i @clerk/astro może zostać obejściem przy użyciu specjalnie spreparowanych żądań HTTP, co pozwala atakującemu ominąć bramkowanie middleware i dotrzeć do chronionych zasobów bez uwierzytelnienia. Podatność ma ocenę CVSS 9.1 i jest sklasyfikowana jako krytyczna.

pub. 2026-04-24
9.1
CVSS
CRITICAL
CVE-2026-6270

Wersje @fastify/middie 9.3.1 i wcześniejsze nie przekazują middleware zarejestrowanego w zakresie nadrzędnym do instancji silnika pluginów potomnych. Skutkuje to możliwością dostępu do chronionych tras przez nieuwierzytelnionych użytkowników, co stanowi krytyczne zagrożenie dla aplikacji opartych na Fastify.

pub. 2026-04-16
9.1
CVSS
CRITICAL
CVE-2026-33807

Biblioteka @fastify/express w wersjach do 4.0.4 włącznie zawiera błąd w obsłudze ścieżek, który powoduje całkowite ominięcie mechanizmów bezpieczeństwa Express middleware. Podatność jest szczególnie groźna, ponieważ nie wymaga żadnej specjalnej konfiguracji ani spreparowanego żądania.

pub. 2026-04-15
9.1
CVSS
CRITICAL
CVE-2026-33808

Biblioteka @fastify/express w wersji 4.0.4 i wcześniejszych nie normalizuje URL-i przed przekazaniem ich do middleware Express, co umożliwia całkowite ominięcie mechanizmów uwierzytelnienia opartych na ścieżkach. Atakujący bez żadnych uprawnień może uzyskać dostęp do chronionych zasobów poprzez proste manipulacje URL.

pub. 2026-04-15
9.1
CVSS
CRITICAL
CVE-2024-38428

GNU Wget w wersjach do 1.24.5 włącznie nieprawidłowo obsługuje znak średnika w podkomponencie userinfo adresu URI. Może to prowadzić do niebezpiecznego zachowania, w którym dane przeznaczone dla sekcji userinfo są błędnie traktowane jako część sekcji host.

pub. 2024-06-16
9.1
CVSS
CRITICAL
CVE-2019-18792

W Suricata 5.0.0 odkryto podatność umożliwiającą ominięcie dowolnej sygnatury opartej na protokole TCP poprzez wstrzyknięcie fałszywego pakietu FIN. Jest to groźne, ponieważ atakujący może skutecznie ukryć złośliwy ruch przed systemem IDS/IPS, całkowicie neutralizując jego ochronę.

pub. 2020-01-06
8.8
CVSS
HIGH
CVE-2026-49473

@cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by mapping HTTP requests to Cedar actions and evaluating authorization policies before allowing requests to proceed. Versions prior to 0.3.0 have an issue where, under certain circumstances, the middleware matches incoming requests against Cedar action mappings using req.originalUrl, which includes the query string, while Express routes requests using only the path component. The middleware uses req.originalUrl to match incoming requests against Cedar action mappings. In Express, req.originalUrl includes the query string, while route matching uses only the path. This creates a divergence between what Cedar authorizes and what Express executes. When an application defines separate actions for overlapping path prefixes with different authorization requirements (for example, GET /users for listing all users with admin-only access, and GET /users/{id} for retrieving a single user with any authenticated user access), an actor can append a query string to bypass the more restrictive policy. Sending GET /users/?x=1 causes the middleware to match against /users/{id} (with id parameter set to ?x=1) and evaluate the less restrictive action, while Express routes the request to the /users list handler. This allows inappropriate access to the more restrictive endpoint. This issue has been addressed in version 0.30. Some workarounds are available. Validate and sanitize incoming request paths before they reach the authorization middleware. Ensure that applications do not rely solely on the middleware for authorization when defining multiple actions on overlapping path prefixes with different permission levels.

pub. 2026-08-13
8.8
CVSS
HIGH
CVE-2023-39481

Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the web server. The issue results from an inconsistency in URI parsing between NGINX and application code. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-20551.

pub. 2024-05-03
8.8
CVSS
HIGH
CVE-2021-28474

Microsoft SharePoint Server Remote Code Execution Vulnerability

pub. 2021-05-11
8.8
CVSS
HIGH
CVE-2018-19966

An issue was discovered in Xen through 4.11.x allowing x86 PV guest OS users to cause a denial of service (host OS crash) or possibly gain host OS privileges because of an interpretation conflict for a union data structure associated with shadow paging. NOTE: this issue exists because of an incorrect fix for CVE-2017-15595.

pub. 2018-12-08
8.8
CVSS
HIGH
CVE-2018-6560

In dbus-proxy/flatpak-proxy.c in Flatpak before 0.8.9, and 0.9.x and 0.10.x before 0.10.3, crafted D-Bus messages to the host can be used to break out of the sandbox, because whitespace handling in the proxy is not identical to whitespace handling in the daemon.

pub. 2018-02-02
Pokazano 20 z 154 podatności
Informacje
ID: CWE-436
Typ: Class
Podatności: 154
MITRE CWE ↗
← Słownik CWE