CWE-1027 2 个 CVE MITRE 定义 ↗

CWE-1027:OWASP Top Ten 2017 Category A1 - Injection

概览

CWE-1027(OWASP Top Ten 2017 Category A1 - Injection)描述一种在漏洞数据库与安全评估中使用的弱点类型;定义、背景与映射 CVE 见下方各节。

安全影响
安全影响:因产品与场景而异;请结合 CVE 记录、严重度评分与 MITRE 说明进行优先级判断。

描述

Weaknesses in this category are related to the A1 category in the OWASP Top Ten 2017.

本库相关 CVE

下列 CVE 在本库中映射到该弱点,并保留以便追溯与检索。

CVE 公开时间 摘要
CVE-2025-59874 2026-06-04 HCL Hive Telco Observability is affected by  a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site vu…
CVE-2021-27021 2021-07-20 A flaw was discovered in Puppet DB, this flaw results in an escalation of privileges which allows the user to delete tables via an SQL query.

内容提交

名称
CWE Content Team
组织
MITRE
日期
2018-01-22
版本
3.1

内容修订

日期 名称 版本 重要性 评论
2014-06-23 CWE Content Team 2.7 updated Relationships
2020-02-24 CWE Content Team 4.0 updated References
2023-04-27 CWE Content Team 4.11 updated Mapping_Notes
2023-06-29 CWE Content Team 4.12 updated Mapping_Notes
2025-09-09 CWE Content Team 4.18 updated References
cvelogic Threat Intelligence