CWE-917 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-917 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 랜섬웨어 캠페인에 사용됨CVE-2021-44228Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI …100.0%심각10.0● 랜섬웨어 캠페인에 사용됨CVE-2022-26134In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists th…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2021-26084In affected versions of Confluence Server and Data Center, an OGNL injection vulnerability exists th…100.0%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2021-45046It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain…100.0%심각9.0● 실제 악용이 확인됨CVE-2022-22963In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing fu…99.9%심각9.8● 실제 악용이 확인됨CVE-2020-10199Sonatype Nexus Repository before 3.21.2 allows JavaEL Injection (issue 1 of 2).99.1%높음8.8● 실제 악용이 확인됨CVE-2022-22947In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code …98.3%심각10.0● 실제 악용이 확인됨CVE-2020-17530Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code …95.9%심각9.8
전체 목록
11건
CVE-2010-1871악용 확인JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not…83.4%높음8.8
CVE-2026-91145Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing att…0.2%높음7.1
CVE-2026-87830In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be co…0.2%심각9.1
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.