检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HJ3M-V758-JWX5 CVE-2021-23797 | Path Traversal in http-server-node | 高危 | npmhttp-server-node | 已审查 | 2022-01-05 23:02 | 2023-09-12 06:36 |
| GHSA-M8GW-HJPR-RJV7 CVE-2021-23450 | Prototype Pollution in dojo |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmdojo |
| 已审查 |
| 2022-01-05 23:01 |
| 2022-01-05 01:43 |
| GHSA-7MQ6-CP5M-F4J5 CVE-2021-44116 | Cross-site Scripting in Anchor CMS | 中危 | Packagistanchorcms/anchor-cms | 已审查 | 2022-01-05 22:54 | 2022-01-05 04:59 |
| GHSA-8489-44MV-GGJ8 CVE-2021-44832 | Improper Input Validation and Injection in Apache Log4j2 | 中危 | Mavenorg.apache.logging.log4j:log4j-core+1 | 已审查 | 2022-01-05 00:14 | 2026-06-09 18:31 |
| GHSA-G5JM-XHWM-9XP9 CVE-2022-22293 | Cross site scripting in dolibarr | 中危 | Packagistdolibarr/dolibarr | 已审查 | 2022-01-03 08:00 | 2022-09-08 07:58 |
| GHSA-VC3P-29H2-GPCP CVE-2021-44716 | golang.org/x/net/http2 allows uncontrolled memory consumption | 高危 | Gogolang.org/x/net/http2 | 已审查 | 2022-01-02 08:00 | 2023-02-08 08:37 |
| GHSA-W6V2-QCHM-GRJ7 CVE-2020-25039 | Insecure permissions on user namespace / fakeroot temporary rootfs in Singularity | 高危 | Gogithub.com/sylabs/singularity | 已审查 | 2021-12-21 02:25 | 2021-05-25 01:12 |
| GHSA-557G-R22W-9WVX CVE-2019-11328 | Incorrect Permission Assignment for Critical Resource in Singularity | 高危 | Gogithub.com/sylabs/singularity | 已审查 | 2021-12-21 02:25 | 2023-03-01 00:47 |
| GHSA-6W7G-P4JH-RF92 CVE-2020-13846 | "Verify All" Returns Success Despite Validation Failures in Singularity | 高危 | Gogithub.com/sylabs/singularity | 已审查 | 2021-12-21 02:24 | 2023-01-21 06:03 |
| GHSA-PMFR-63C2-JR5C CVE-2020-13845 | Execution Control List (ECL) Is Insecure in Singularity | 高危 | Gogithub.com/sylabs/singularity | 已审查 | 2021-12-21 02:24 | 2023-01-21 06:02 |
| GHSA-G54H-M393-CPWQ | devices resource list treated as a blacklist by default | 低危 | Gogithub.com/opencontainers/runc | 已审查 | 2021-12-21 02:21 | 2021-05-25 04:46 |
| GHSA-GP4J-W3VJ-7299 CVE-2016-9962 | Information Exposure in RunC | 中危 | Gogithub.com/opencontainers/runc | 已审查 | 2021-12-21 02:21 | 2021-05-21 00:22 |
| GHSA-Q3J5-32M5-58C2 CVE-2016-3697 | Privilege Elevation in runc | 高危 | Gogithub.com/opencontainers/runc | 已审查 | 2021-12-21 02:21 | 2024-05-21 03:40 |
| GHSA-F3W5-V9XX-RP8P | Signature verification failure in Tendermint | 中危 | Gogithub.com/tendermint/tendermint | 已审查 | 2021-12-21 02:17 | 2021-05-21 04:10 |
| GHSA-6JQJ-F58P-MRW3 CVE-2020-15091 | Denial of Service in TenderMint | 中危 | Gogithub.com/tendermint/tendermint | 已审查 | 2021-12-21 02:17 | 2024-06-01 01:46 |
| GHSA-MX43-R985-5H4M CVE-2020-12283 | Open redirect vulnerability in Sourcegraph | 中危 | Gogithub.com/sourcegraph/sourcegraph | 已审查 | 2021-12-21 02:12 | 2023-10-02 22:32 |
| GHSA-RRM8-32G4-W8M3 CVE-2017-1000069 | Cross-site Request Forgery (CSRF) | 高危 | Gogithub.com/bitly/oauth2_proxy | 已审查 | 2021-12-21 02:04 | 2021-05-13 02:30 |
| GHSA-JM34-XM8M-W958 CVE-2017-1000070 | Open Redirect in oauth2_proxy | 中危 | Gogithub.com/bitly/oauth2_proxy | 已审查 | 2021-12-21 02:04 | 2021-05-20 06:31 |
| GHSA-QQXW-M5FJ-F7GV CVE-2020-5233 | The pattern '/\domain.com' is not disallowed when redirecting, allowing for open redirect | 中危 | Gogithub.com/oauth2-proxy/oauth2-proxy | 已审查 | 2021-12-21 02:02 | 2021-05-25 05:20 |
| GHSA-J7PX-6HWJ-HPJG CVE-2020-11053 | Open Redirect in OAuth2 Proxy | 高危 | Gogithub.com/oauth2-proxy/oauth2-proxy | 已审查 | 2021-12-21 01:59 | 2024-02-15 14:33 |
| GHSA-5M6C-JP6F-2VCV CVE-2020-4037 | Open Redirect in OAuth2 Proxy | 中危 | Gogithub.com/oauth2-proxy/oauth2-proxy | 已审查 | 2021-12-21 01:58 | 2021-05-25 04:58 |
| GHSA-627P-RR78-99RJ CVE-2020-5415 | GitLab auth uses full name instead of username as user ID, allowing impersonation | 高危 | Gogithub.com/concourse/concourse+1 | 已审查 | 2021-12-21 01:56 | 2025-07-23 00:13 |
| GHSA-M9HP-7R99-94H5 CVE-2020-26290 | Critical security issues in XML encoding in github.com/dexidp/dex | 严重 | Gogithub.com/dexidp/dex+1 | 已审查 | 2021-12-21 01:53 | 2021-05-22 04:49 |
| GHSA-2X32-JM95-2CPX CVE-2020-27847 | Authentication Bypass in dex | 严重 | Gogithub.com/dexidp/dex | 已审查 | 2021-12-21 01:52 | 2021-06-02 01:58 |
| GHSA-QC22-QWM9-J8RX | Remote Code Execution in npm-groovy-lint | 严重 | npmnpm-groovy-lint | 已审查 | 2021-12-21 00:59 | 2021-12-21 00:57 |