检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RF3M-MHV7-X39F CVE-2015-5250 | Denial of Service in OpenShift Origin | 中危 | Gogithub.com/openshift/origin | 已审查 | 2021-12-21 00:58 | 2023-02-14 02:18 |
| GHSA-M3FM-H5JP-Q79P CVE-2016-1906 | Authorization bypass in Openshift |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Gogithub.com/openshift/origin |
| 已审查 |
| 2021-12-21 00:58 |
| 2023-02-04 04:37 |
| GHSA-68WM-PFJF-WQP6 CVE-2021-32637 | Authelia vulnerable to an authentication bypassed with malformed request URI on nginx | 严重 | Gogithub.com/authelia/authelia/v4 | 已审查 | 2021-12-21 00:57 | 2024-04-22 22:49 |
| GHSA-WXC4-F4M6-WWQV CVE-2019-11254 | Excessive Platform Resource Consumption within a Loop in Kubernetes | 中危 | Gogithub.com/go-yaml/yaml+1 | 已审查 | 2021-12-21 00:55 | 2023-02-10 01:45 |
| GHSA-P6XC-XR62-6R2G CVE-2021-45105 | Apache Log4j2 vulnerable to Improper Input Validation and Uncontrolled Recursion | 高危 | Mavenorg.apache.logging.log4j:log4j-core+1 | 已审查 | 2021-12-19 02:00 | 2026-06-09 18:26 |
| GHSA-FPFV-JQM9-F5JM CVE-2021-34141 | Incorrect Comparison in NumPy | 中危 | PyPInumpy | 已审查 | 2021-12-18 08:00 | 2022-06-22 04:12 |
| GHSA-QJ27-32WP-GHRG CVE-2021-41498 | Pyo Buffer Overflow Vulnerability | 高危 | PyPIpyo | 已审查 | 2021-12-18 08:00 | 2024-11-27 00:13 |
| GHSA-74XW-GWFM-7PV7 CVE-2021-41497 | bounter Null pointer reference | 高危 | PyPIbounter | 已审查 | 2021-12-18 08:00 | 2024-11-22 06:18 |
| GHSA-3W6P-8F82-GW8R | Using JMSAppender in log4j configuration may lead to deserialization of untrusted data | 高危 | Mavenru.yandex.clickhouse:clickhouse-jdbc-bridge | 已审查 | 2021-12-18 04:42 | 2021-12-18 04:34 |
| GHSA-G7P8-R2CH-4RMF CVE-2020-35215 | Malicious Atomix node queries expose sensitive information | 中危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:41 | 2022-01-05 02:56 |
| GHSA-7FR2-94H7-CCG2 CVE-2020-35209 | An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to join a target cluster via providing configuration information. | 高危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:41 | 2022-01-05 02:58 |
| GHSA-M4H3-7MC2-V295 CVE-2020-35214 | An issue in Atomix v3.1.5 allows a malicious Atomix node to remove states of ONOS storage via abuse of primitive operations. | 高危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:41 | 2022-01-05 03:00 |
| GHSA-MF27-WG66-M8F5 CVE-2020-35210 | A vulnerability in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via a Raft session flooding attack using Raft OpenSessionRequest messages. | 中危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:41 | 2022-01-05 02:57 |
| GHSA-6VVH-5794-VPMJ CVE-2020-35216 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false member down event messages. | 中危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:40 | 2022-01-05 02:57 |
| GHSA-2FQW-684C-PVP7 CVE-2020-35213 | An issue in Atomix v3.1.5 allows attackers to cause a denial of service (DoS) via false link event messages sent to a master ONOS node. | 高危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:40 | 2022-01-05 02:59 |
| GHSA-4JHC-WJR3-PWH2 CVE-2020-35211 | An issue in Atomix v3.1.5 allows unauthorized Atomix nodes to become the lead node. | 高危 | Mavenio.atomix:atomix | 已审查 | 2021-12-18 04:40 | 2022-01-05 02:59 |
| GHSA-668Q-QRV7-99FM CVE-2021-42550 | Deserialization of Untrusted Data in logback | 中危 | Mavench.qos.logback:logback-core | 已审查 | 2021-12-18 04:00 | 2021-12-18 03:25 |
| GHSA-RPG7-Q4CV-P466 CVE-2021-4123 | livehelperchat is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistremdex/livehelperchat | 已审查 | 2021-12-18 04:00 | 2022-01-05 02:52 |
| GHSA-J85F-XW9X-FFWP CVE-2021-4121 | yetiforcecrm is vulnerable to Cross-site Scripting | 中危 | Packagistyetiforce/yetiforce-crm | 已审查 | 2021-12-18 04:00 | 2022-01-05 02:52 |
| GHSA-XMGJ-5FH3-XJMM CVE-2021-43840 | Path traversal when MessageBus::Diagnostics is enabled | 中危 | RubyGemsmessage_bus | 已审查 | 2021-12-18 03:59 | 2021-12-18 03:34 |
| GHSA-55XV-F85C-248Q CVE-2021-43838 | Regular Expression Denial of Service (ReDoS) in jsx-slack | 低危 | npmjsx-slack | 已审查 | 2021-12-18 03:59 | 2022-01-05 03:52 |
| GHSA-Q868-C4VW-QJX3 CVE-2021-44350 | ThinkPHP5 SQL Injection vulnerability | 严重 | Packagisttopthink/framework | 已审查 | 2021-12-17 08:00 | 2024-04-25 07:02 |
| GHSA-Q34H-97WF-8R8J CVE-2021-43837 | vault-cli contains possible RCE when reading user-defined data | 中危 | PyPIvault-cli | 已审查 | 2021-12-17 05:02 | 2024-11-19 06:46 |
| GHSA-J7C3-96RF-JRRP | Critical vulnerability in log4j may affect generated PEAR projects | 严重 | Mavende.averbis.textanalysis:pear-archetype | 已审查 | 2021-12-17 05:01 | 2021-12-17 02:57 |
| GHSA-7V7W-F7C6-F829 CVE-2021-4111 | YetiForceCRM is vulnerable to Business Logic Errors because product amount can be a negative number | 高危 | Packagistyetiforce/yetiforce-crm | 已审查 | 2021-12-17 05:01 | 2022-08-12 02:47 |