检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-F99G-PG48-WRFC CVE-2021-3932 | twill is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistarea17/twill | 已审查 | 2021-11-16 07:19 | 2021-11-18 05:13 |
| GHSA-533P-CP2G-99WP CVE-2021-3931 | snipe-it is vulnerable to Cross-Site Request Forgery (CSRF) |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Packagistsnipe/snipe-it |
| 已审查 |
| 2021-11-16 07:19 |
| 2021-11-18 05:12 |
| GHSA-Q2CV-94XM-QVG4 CVE-2021-3921 | firefly-iii is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistgrumpydictator/firefly-iii | 已审查 | 2021-11-16 07:18 | 2021-11-18 05:12 |
| GHSA-W2F4-HXPM-MQ98 CVE-2021-3915 | bookstack is vulnerable to Unrestricted Upload of File with Dangerous Type | 高危 | Packagistssddanbrown/bookstack | 已审查 | 2021-11-16 07:17 | 2021-11-18 05:12 |
| GHSA-4999-659W-MQ36 CVE-2021-41266 | Authentication bypass issue in the Operator Console | 高危 | Gogithub.com/minio/console | 已审查 | 2021-11-16 07:16 | 2021-11-16 04:27 |
| GHSA-PJJF-HC4Q-G298 CVE-2021-3775 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistshowdoc/showdoc | 已审查 | 2021-11-16 07:16 | 2021-11-18 05:11 |
| GHSA-X5JP-9FMM-M9PF CVE-2021-3683 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistshowdoc/showdoc | 已审查 | 2021-11-16 07:13 | 2021-11-18 05:11 |
| GHSA-M4HJ-WG2R-QPCR CVE-2021-3776 | showdoc is vulnerable to Cross-Site Request Forgery (CSRF) | 中危 | Packagistshowdoc/showdoc | 已审查 | 2021-11-16 07:13 | 2021-11-18 05:10 |
| GHSA-VX6V-XG64-PMR8 CVE-2021-3945 | Cross-site Scripting in django-helpdesk | 高危 | PyPIdjango-helpdesk | 已审查 | 2021-11-16 07:12 | 2024-09-17 06:11 |
| GHSA-844M-CPR9-JCMH CVE-2021-41263 | Rails Multisite secure/signed cookies share secrets between sites in a multi-site application | 中危 | RubyGemsrails_multisite | 已审查 | 2021-11-16 01:54 | 2022-08-12 02:31 |
| GHSA-5XP3-JFQ3-5Q8X CVE-2021-3572 | Improper Input Validation in pip | 高危 | PyPIpip | 已审查 | 2021-11-16 01:45 | 2024-10-12 05:24 |
| GHSA-W6V7-W58J-PG5R CVE-2021-41038 | Improper Verification of Communication Channel in @theia/plugin-ext | 中危 | npm@theia/plugin-ext | 已审查 | 2021-11-16 01:40 | 2021-11-15 22:59 |
| GHSA-HFM8-2Q22-H7HV CVE-2021-43561 | Cross-site Scripting in pegasus/google-for-jobs | 中危 | Packagistpegasus/google-for-jobs | 已审查 | 2021-11-16 01:39 | 2021-11-18 05:24 |
| GHSA-43G8-79X3-J898 CVE-2021-43564 | Unrestricted access to predictable file paths in hov/jobfair | 高危 | Packagisthov/jobfair | 已审查 | 2021-11-16 01:36 | 2021-11-18 05:24 |
| GHSA-35RF-V2JV-GFG7 CVE-2021-41254 | Privilege escalation to cluster admin on multi-tenant environments | 高危 | Gogithub.com/fluxcd/kustomize-controller | 已审查 | 2021-11-16 01:35 | 2021-11-13 02:57 |
| GHSA-6MV9-QCX2-3HH3 CVE-2021-43174 | Memory exhaustion in routinator | 高危 | crates.ioroutinator | 已审查 | 2021-11-11 08:55 | 2021-11-15 22:48 |
| GHSA-Q9Q6-F556-GPM7 CVE-2021-43571 | Improper Verification of Cryptographic Signature in starkbank-ecdsa | 严重 | npmstarkbank-ecdsa | 已审查 | 2021-11-11 04:58 | 2021-11-15 22:44 |
| GHSA-J3JW-J2J8-2WV9 CVE-2021-43569 | Improper Verification of Cryptographic Signature in starkbank-ecdsa | 严重 | NuGetstarkbank-ecdsa | 已审查 | 2021-11-11 04:58 | 2021-11-15 22:43 |
| GHSA-R28H-X6HV-2FQ3 CVE-2021-43570 | Improper Verification of Cryptographic Signature in starkbank-ecdsa | 严重 | Mavencom.starkbank.ellipticcurve:starkbank-ecdsa | 已审查 | 2021-11-11 04:48 | 2025-01-21 00:11 |
| GHSA-92VM-MXJF-JQF3 CVE-2021-43572 | Improper Verification of Cryptographic Signature in starkbank-ecdsa | 严重 | PyPIstarkbank-ecdsa | 已审查 | 2021-11-11 04:41 | 2024-10-25 22:49 |
| GHSA-G9WH-3VRX-R7HG CVE-2021-3912 | OctoRPKI crashes when processing GZIP bomb returned via malicious repository | 中危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-11 04:39 | 2021-11-11 02:19 |
| GHSA-G5GJ-9GGF-9VMQ CVE-2021-3908 | Infinite certificate chain depth results in OctoRPKI running forever | 中危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-11 04:38 | 2023-10-02 23:58 |
| GHSA-8CVR-4RRF-F244 CVE-2021-3909 | Infinite open connection causes OctoRPKI to hang forever | 中危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-11 04:15 | 2023-10-02 23:56 |
| GHSA-5MXH-2QFV-4G7J CVE-2021-3910 | NUL character in ROA causes OctoRPKI to crash | 高危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-11 04:15 | 2026-04-16 05:11 |
| GHSA-CQH2-VC2F-Q4FH CVE-2021-3907 | Arbitrary filepath traversal via URI injection | 高危 | Gogithub.com/cloudflare/cfrpki | 已审查 | 2021-11-11 04:08 | 2021-11-11 02:16 |