检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VC4R-J8J6-3FP6 CVE-2022-23112 | Missing permission check in Jenkins Publish Over SSH Plugin | 中危 | Mavenorg.jenkins-ci.plugins:publish-over-ssh | 已审查 | 2022-01-13 08:00 | 2023-12-15 02:28 |
| GHSA-R3RR-WPH6-9638 CVE-2022-23114 | Password stored in plain text by Jenkins Publish Over SSH Plugin |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Mavenorg.jenkins-ci.plugins:publish-over-ssh |
| 已审查 |
| 2022-01-13 08:00 |
| 2022-11-30 05:26 |
| GHSA-MH8G-8JWP-Q6XW CVE-2022-23115 | CSRF vulnerability in Jenkins batch task Plugin | 中危 | Mavenorg.jenkins-ci.plugins:batch-task | 已审查 | 2022-01-13 08:00 | 2023-10-28 00:21 |
| GHSA-J8RG-4HJM-8R95 CVE-2022-23113 | Path traversal vulnerability in Jenkins Publish Over SSH Plugin | 中危 | Mavenorg.jenkins-ci.plugins:publish-over-ssh | 已审查 | 2022-01-13 08:00 | 2022-11-30 05:23 |
| GHSA-CW68-XMM4-C83R CVE-2022-23117 | Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows retrieving all credentials | 中危 | Mavenorg.conjur.jenkins:conjur-credentials | 已审查 | 2022-01-13 08:00 | 2022-11-30 05:35 |
| GHSA-884C-9WWH-9P6V CVE-2022-23111 | CSRF vulnerability and missing permission checks in Jenkins Publish Over SSH Plugin | 中危 | Mavenorg.jenkins-ci.plugins:publish-over-ssh | 已审查 | 2022-01-13 08:00 | 2023-10-28 00:57 |
| GHSA-G7FX-MMJC-R7GV CVE-2022-23116 | Agent-to-controller security bypass in Jenkins Conjur Secrets Plugin allows decrypting secrets | 中危 | Mavenorg.conjur.jenkins:conjur-credentials | 已审查 | 2022-01-13 08:00 | 2022-11-30 05:30 |
| GHSA-8XJP-RP29-V5J8 CVE-2022-23118 | Agent-to-controller security bypass in Jenkins Debian Package Builder Plugin | 高危 | Mavenru.yandex.jenkins.plugins.debuilder:debian-package-builder | 已审查 | 2022-01-13 08:00 | 2023-06-28 06:18 |
| GHSA-6GF2-PVQW-37PH CVE-2021-22060 | Log entry injection in Spring Framework | 中危 | Mavenorg.springframework:spring-core | 已审查 | 2022-01-13 07:04 | 2022-01-19 06:38 |
| GHSA-GJM5-83CW-P3P2 CVE-2021-23568 | Prototype Pollution in extend2 | 高危 | npmextend2 | 已审查 | 2022-01-13 06:59 | 2022-01-12 02:11 |
| GHSA-PWM7-QR6J-3VJG CVE-2021-23594 | Prototype Pollution in realms-shim | 严重 | npmrealms-shim | 已审查 | 2022-01-13 06:56 | 2022-01-12 02:14 |
| GHSA-8QVX-F5GF-G43V CVE-2022-0174 | Logic error in dolibarr | 中危 | Packagistdolibarr/dolibarr | 已审查 | 2022-01-13 06:54 | 2022-01-20 23:34 |
| GHSA-VP5X-3V8R-QPRW CVE-2021-43297 | Deserialization of Untrusted Data in Dubbo | 严重 | Mavenorg.apache.dubbo:dubbo | 已审查 | 2022-01-13 06:51 | 2022-01-20 02:25 |
| GHSA-74FJ-2J2H-C42Q CVE-2022-0155 | Exposure of sensitive information in follow-redirects | 高危 | npmfollow-redirects | 已审查 | 2022-01-13 06:46 | 2022-01-20 23:34 |
| GHSA-7W54-GP8X-F33M CVE-2022-21671 | Potential exposure of tokens to an Unauthorized Actor | 中危 | npm@replit/crosis | 已审查 | 2022-01-13 06:44 | 2023-07-25 03:32 |
| GHSA-4H9C-V5VG-5M6M CVE-2021-21408 | Access to restricted PHP code by dynamic static class access in smarty | 高危 | Packagistsmarty/smarty | 已审查 | 2022-01-13 06:43 | 2022-01-20 23:33 |
| GHSA-29GP-2C3M-3J6M CVE-2021-29454 | Sandbox Escape by math function in smarty | 高危 | Packagistsmarty/smarty | 已审查 | 2022-01-13 06:43 | 2022-01-20 23:34 |
| GHSA-M7VP-HQWV-7M5X | Unbounded memory usage on exposed HTTP/2 (non-gRPC) endpoints | 高危 | Gogithub.com/spiffe/spire | 已审查 | 2022-01-13 06:33 | 2022-01-12 00:45 |
| GHSA-QC9X-GJCV-465W CVE-2022-21668 | Pipenv's requirements.txt parsing allows malicious index url in comments | 高危 | PyPIpipenv | 已审查 | 2022-01-13 06:29 | 2024-10-12 05:22 |
| GHSA-6VFC-QV3F-VR6C CVE-2022-21670 | Uncontrolled Resource Consumption in markdown-it | 中危 | npmmarkdown-it | 已审查 | 2022-01-13 06:20 | 2022-01-20 02:25 |
| GHSA-HRGX-7J6V-XJ82 CVE-2022-0087 | Reflected cross-site scripting (XSS) vulnerability | 高危 | npm@keystone-6/auth+1 | 已审查 | 2022-01-13 05:55 | 2022-01-20 01:42 |
| GHSA-RRGW-3HG3-9X8C | XSS vulnerability in translations | 中危 | Packagistoro/platform | 已审查 | 2022-01-13 05:49 | 2022-01-11 05:39 |
| GHSA-2W8G-M5J8-7M87 | Zalgo-like output that crashes the server | 严重 | npm@soketi/soketi | 已审查 | 2022-01-13 05:45 | 2022-01-11 05:37 |
| GHSA-PW3C-H7WP-CVHX CVE-2022-22815 | Improper Initialization in Pillow | 中危 | PyPIpillow | 已审查 | 2022-01-13 04:07 | 2024-10-12 05:09 |
| GHSA-XRCV-F9GM-V42C CVE-2022-22816 | Out-of-bounds Read in Pillow | 中危 | PyPIpillow | 已审查 | 2022-01-13 04:07 | 2024-10-12 05:27 |