检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3QPG-33WR-533J CVE-2021-46365 | Improper Restriction of XML External Entity Reference in Magnolia CMS | 高危 | Maveninfo.magnolia:magnolia-core | 已审查 | 2022-02-12 08:00 | 2022-04-21 03:13 |
| GHSA-M658-P24X-P74R | Duplicate Advisory: TLS certificate validation error in mellium.im/xmpp |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Gomellium.im/xmpp |
| 已审查 |
| 2022-02-12 08:00 |
| 2024-05-21 05:04 |
| GHSA-W3WF-CFX3-6GCX CVE-2020-26276 | SAML authentication vulnerability due to stdlib XML parsing | 高危 | Gogithub.com/fleetdm/fleet/v4 | 已审查 | 2022-02-12 07:59 | 2022-02-12 07:59 |
| GHSA-XHQQ-X44F-9FGG CVE-2020-29509 | Authentication Bypass in github.com/russellhaering/gosaml2 | 严重 | Gogithub.com/russellhaering/gosaml2 | 已审查 | 2022-02-12 07:58 | 2021-05-22 05:11 |
| GHSA-H2FG-54X9-5QHQ CVE-2020-26521 | Nil dereference in NATS JWT, DoS of nats-server | 高危 | Gogithub.com/nats-io/jwt | 已审查 | 2022-02-12 07:43 | 2025-10-04 03:29 |
| GHSA-4W5X-X539-PPF5 CVE-2020-26892 | Incorrect handling of credential expiry by /nats-io/nats-server | 严重 | Gogithub.com/nats-io/jwt | 已审查 | 2022-02-12 07:42 | 2025-10-04 03:21 |
| GHSA-FQFH-778M-2V32 | GitHub CLI can execute a git binary from the current directory | 中危 | Gogithub.com/cli/cli | 已审查 | 2022-02-12 07:41 | 2021-05-22 06:06 |
| GHSA-H2X7-2FF6-V32P CVE-2022-2583 | gobase subject to Incorrect routing of some HTTP requests when using httpauth due to a race condition | 低危 | Gogithub.com/ntbosscher/gobase | 已审查 | 2022-02-12 07:39 | 2026-02-03 05:00 |
| GHSA-4G4P-42WC-9F3M CVE-2020-27955 | Git LFS can execute a Git binary from the current directory | 严重 | Gogithub.com/git-lfs/git-lfs | 已审查 | 2022-02-12 07:39 | 2022-04-21 00:25 |
| GHSA-HV53-VF5M-8Q94 | personnummer/go vulnerable to Improper Input Validation | 低危 | Gogithub.com/personnummer/go | 已审查 | 2022-02-12 07:28 | 2022-09-20 06:53 |
| GHSA-742W-89GC-8M9C CVE-2020-15157 | containerd v1.2.x can be coerced into leaking credentials during image pull | 中危 | Gogithub.com/containerd/containerd | 已审查 | 2022-02-12 07:27 | 2022-02-12 07:27 |
| GHSA-F5PG-7WFW-84Q9 CVE-2020-8911 | CBC padding oracle issue in AWS S3 Crypto SDK for golang | 中危 | Gogithub.com/aws/aws-sdk-go | 已审查 | 2022-02-12 07:26 | 2024-05-21 05:15 |
| GHSA-76WF-9VGP-PJ7W | Duplicate Advisory: Unencrypted md5 plaintext hash in metadata in AWS S3 Crypto SDK for golang 已撤回 | 中危 | Gogithub.com/aws/aws-sdk-go | 已审查 | 2022-02-12 07:26 | 2026-02-04 03:37 |
| GHSA-7F33-F4F5-XWGW CVE-2020-8912 | In-band key negotiation issue in AWS S3 Crypto SDK for golang | 低危 | Gogithub.com/aws/aws-sdk-go | 已审查 | 2022-02-12 07:23 | 2024-05-21 05:14 |
| GHSA-6QQ8-5WQ3-86RP CVE-2020-15129 | Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header | 中危 | Gogithub.com/containous/traefik+7 | 已审查 | 2022-02-12 07:19 | 2022-08-05 04:56 |
| GHSA-5X29-3HR9-6WPW CVE-2020-8918 | TPM 1.2 key authorization values vulnerable to TPM transport eavesdropper in go-tpm | 高危 | Gogithub.com/google/go-tpm | 已审查 | 2022-02-12 07:18 | 2023-08-30 05:08 |
| GHSA-Q9X4-Q76F-5H5J CVE-2019-19030 | Unauthenticated users can exploit an enumeration vulnerability in Harbor (CVE-2019-19030) | 中危 | Gogithub.com/goharbor/harbor | 已审查 | 2022-02-12 07:17 | 2023-01-10 23:48 |
| GHSA-33P6-FX42-7RF5 CVE-2020-13788 | Harbor is vulnerable to a limited Server-Side Request Forgery (SSRF) (CVE-2020-13788) | 低危 | Gogithub.com/goharbor/harbor | 已审查 | 2022-02-12 07:17 | 2021-05-25 03:08 |
| GHSA-RMJ8-8HHH-GV5H CVE-2022-23634 | Puma used with Rails may lead to Information Exposure | 高危 | RubyGemspuma | 已审查 | 2022-02-12 05:33 | 2022-08-17 03:43 |
| GHSA-WH98-P28R-VRC9 CVE-2022-23633 | Exposure of information in Action Pack | 高危 | RubyGemsactionpack | 已审查 | 2022-02-12 04:49 | 2022-02-24 21:15 |
| GHSA-45W3-V3G4-54PM | Chrono has potential segfault issue in SPIFFE authenticator | 低危 | crates.ioparsec-service | 已审查 | 2022-02-12 03:11 | 2022-09-13 04:44 |
| GHSA-QH73-QC3P-RJV2 CVE-2021-23597 | Uncaught Exception in fastify-multipart | 高危 | npmfastify-multipart | 已审查 | 2022-02-12 02:57 | 2022-02-24 06:11 |
| GHSA-GR23-G276-XC73 CVE-2021-22954 | Cross Site Request Forgery in concrete5/concrete5 | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2022-02-11 08:00 | 2022-02-17 06:54 |
| GHSA-JQMC-79GX-7G8P CVE-2022-0532 | Incorrect Permission Assignment for Critical Resource in CRI-O | 中危 | Gogithub.com/cri-o/cri-o | 已审查 | 2022-02-11 08:00 | 2022-02-24 06:00 |
| GHSA-WMJ9-XH24-J4GX CVE-2022-0558 | Cross-site Scripting in microweber | 中危 | Packagistmicroweber/microweber | 已审查 | 2022-02-11 08:00 | 2022-02-24 05:58 |