检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3PQH-P72C-FJ85 CVE-2021-3978 | Improper Preservation of Permissions in github.com/cloudflare/cfrpki/cmd/octorpki | 高危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-20 03:34 | 2025-01-30 00:56 |
| GHSA-GPQC-4PP7-5954 | Duplicate Advisory: Authentication Bypass by CSRF Weakness |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
RubyGemsspree_auth_devise |
| 已审查 |
| 2021-11-19 04:15 |
| 2025-07-02 03:19 |
| GHSA-8XFW-5Q82-3652 | Duplicate Advisory: Authentication Bypass by CSRF Weakness 已撤回 | 严重 | RubyGemsspree_auth_devise | 已审查 | 2021-11-19 04:15 | 2025-07-02 02:04 |
| GHSA-6MQR-Q86Q-6GWR | Duplicate Advisory: Authentication Bypass by CSRF Weakness 已撤回 | 严重 | RubyGemsspree_auth_devise | 已审查 | 2021-11-19 04:15 | 2025-07-02 02:05 |
| GHSA-26XX-M4Q2-XHQ8 CVE-2021-41275 | Spree Auth Devise vulnerability allows for authentication bypass through CSRF weakness | 严重 | RubyGemsspree_auth_devise | 已审查 | 2021-11-19 04:14 | 2025-07-02 01:28 |
| GHSA-5629-8855-GF4G | Authentication Bypass by CSRF Weakness | 严重 | RubyGemssolidus_core | 已审查 | 2021-11-19 04:12 | 2021-11-18 05:07 |
| GHSA-XM34-V85H-9PG2 CVE-2021-41274 | Authentication Bypass by CSRF Weakness | 严重 | RubyGemssolidus_auth_devise | 已审查 | 2021-11-19 04:09 | 2021-11-18 03:57 |
| GHSA-MC8V-MGRF-8F4M CVE-2021-41190 | Clarify Content-Type handling | 低危 | Gogithub.com/opencontainers/distribution-spec | 已审查 | 2021-11-19 00:13 | 2021-12-13 21:12 |
| GHSA-5J5W-G665-5M35 | Ambiguous OCI manifest parsing | 低危 | Gogithub.com/containerd/containerd | 已审查 | 2021-11-19 00:08 | 2023-03-30 22:50 |
| GHSA-77VH-XPMG-72QH | Clarify `mediaType` handling | 低危 | Gogithub.com/opencontainers/image-spec | 已审查 | 2021-11-19 00:02 | 2021-11-25 03:43 |
| GHSA-WWGQ-9JHF-QGW6 CVE-2021-41273 | Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys | 中危 | Packagistpterodactyl/panel | 已审查 | 2021-11-18 23:46 | 2021-11-18 05:08 |
| GHSA-PPQ7-88C7-Q879 CVE-2021-25976 | Cross-Site Request Forgery in PiranhaCMS | 高危 | NuGetPiranha | 已审查 | 2021-11-18 07:42 | 2021-11-18 06:34 |
| GHSA-VPFP-5GWQ-G533 CVE-2021-37580 | Improper Authentication in Apache ShenYu Admin | 严重 | Mavenorg.apache.shenyu:shenyu-admin | 已审查 | 2021-11-18 07:15 | 2023-09-06 06:18 |
| GHSA-7H26-63M7-QHF2 CVE-2021-41165 | HTML comments vulnerability allowing to execute JavaScript code | 高危 | npmckeditor/ckeditor+1 | 已审查 | 2021-11-18 05:58 | 2022-02-09 04:39 |
| GHSA-PVMX-G8H5-CPRJ CVE-2021-41164 | Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML | 高危 | npmckeditor4 | 已审查 | 2021-11-18 05:55 | 2022-02-09 04:39 |
| GHSA-364W-9G92-3GRQ CVE-2021-43617 | Withdrawn: Laravel Framework does not sufficiently block the upload of executable PHP content. 已撤回 | 中危 | Packagistlaravel/framework | 已审查 | 2021-11-17 07:40 | 2021-11-18 06:04 |
| GHSA-RRC9-GQF8-8RWG CVE-2020-28472 | Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader | 高危 | npm@aws-sdk/shared-ini-file-loader+1 | 已审查 | 2021-11-17 05:26 | 2021-04-07 04:37 |
| GHSA-H352-G5VW-3926 CVE-2021-43620 | Improper Input Validation in fruity | 高危 | crates.iofruity | 已审查 | 2021-11-17 01:26 | 2023-06-14 01:27 |
| GHSA-R7CJ-8HJG-X622 CVE-2021-43608 | DBAL 3 SQL Injection Security Vulnerability | 严重 | Packagistdoctrine/dbal | 已审查 | 2021-11-17 01:25 | 2021-12-16 22:11 |
| GHSA-CQ58-R77C-5JJW CVE-2021-41258 | Cross-site scripting (XSS) from image block content in the site frontend | 中危 | Packagistgetkirby/cms | 已审查 | 2021-11-17 01:04 | 2021-11-16 23:49 |
| GHSA-X7J7-QP7J-HW3Q CVE-2021-41252 | Cross-site scripting (XSS) from writer field content in the site frontend | 中危 | Packagistgetkirby/cms | 已审查 | 2021-11-17 01:04 | 2021-11-16 23:46 |
| GHSA-QG54-694P-WGPP CVE-2021-41817 | Regular expression denial of service vulnerability (ReDoS) in date | 高危 | RubyGemsdate | 已审查 | 2021-11-16 08:32 | 2024-01-25 03:18 |
| GHSA-WMPV-C2JP-J2XG | ERC1155Supply vulnerability in OpenZeppelin Contracts | 低危 | npm@openzeppelin/contracts+1 | 已审查 | 2021-11-16 07:28 | 2021-11-16 06:27 |
| GHSA-P9M8-27X8-RG87 CVE-2021-41269 | Critical vulnerability found in cron-utils | 严重 | Mavencom.cronutils:cron-utils | 已审查 | 2021-11-16 07:27 | 2021-11-16 06:23 |
| GHSA-2CQG-Q7JM-J35C CVE-2021-3938 | snipe-it is vulnerable to Cross-site Scripting | 低危 | Packagistsnipe/snipe-it | 已审查 | 2021-11-16 07:19 | 2021-11-18 05:13 |