检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-F6JP-J6W3-W9HM CVE-2021-41303 | Apache Shiro vulnerable to a specially crafted HTTP request causing an authentication bypass | 严重 | Mavenorg.apache.shiro:shiro-core | 已审查 | 2021-09-21 04:18 | 2022-08-16 04:07 |
| GHSA-92V9-XH2Q-FQ9F CVE-2021-23442 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Prototype Pollution in cookiex/deep |
| 高危 |
npm@cookiex/deep |
| 已审查 |
| 2021-09-21 04:12 |
| 2022-12-03 12:00 |
| GHSA-468Q-V4JJ-485H CVE-2021-3804 | Inefficient Regular Expression Complexity in taro | 高危 | npm@tarojs/helper | 已审查 | 2021-09-21 04:09 | 2021-09-21 04:00 |
| GHSA-Q879-9G95-56MX CVE-2021-39219 | Wrong type for `Linker`-define functions when used across two `Engine`s | 中危 | crates.iowasmtime | 已审查 | 2021-09-21 03:54 | 2024-11-20 02:05 |
| GHSA-4873-36H9-WV49 CVE-2021-39218 | Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime | 中危 | crates.iowasmtime | 已审查 | 2021-09-21 03:54 | 2024-11-20 02:04 |
| GHSA-V4CP-H94R-M7XF CVE-2021-39216 | Use after free passing `externref`s to Wasm in Wasmtime | 中危 | crates.iowasmtime | 已审查 | 2021-09-21 03:54 | 2024-11-20 02:00 |
| GHSA-579X-CJVR-CQJ9 CVE-2021-39189 | Observable Response Discrepancy in Lost Password Service | 中危 | Packagistpimcore/pimcore | 已审查 | 2021-09-21 03:53 | 2021-09-18 02:38 |
| GHSA-JP7F-GRCV-6MJF CVE-2021-39208 | Partial path traversal in sharpcompress | 中危 | NuGetSharpCompress | 已审查 | 2021-09-21 03:53 | 2024-07-08 22:33 |
| GHSA-22GH-3R9Q-XF38 CVE-2021-39214 | Lacking Protection against HTTP Request Smuggling in mitmproxy | 严重 | PyPImitmproxy | 已审查 | 2021-09-21 03:53 | 2024-10-02 03:26 |
| GHSA-FHV8-FX5F-7FXF CVE-2021-39227 | Prototype Pollution in the merge and clone helper methods | 中危 | npmzrender | 已审查 | 2021-09-21 03:53 | 2024-12-07 02:20 |
| GHSA-MC22-5Q92-8V85 CVE-2021-39228 | Memory Safety Issue when using patch or merge on state and assign the result back to state | 中危 | crates.iotremor-script | 已审查 | 2021-09-21 03:52 | 2021-09-18 01:50 |
| GHSA-WFRJ-QQC2-83CM | Remote command injection when using sendmail email transport | 中危 | npmghost | 已审查 | 2021-09-21 03:52 | 2021-09-18 01:48 |
| GHSA-84P7-FH9C-6G8H | Prototype Pollution in mixme | 高危 | npmmixme | 已审查 | 2021-09-21 03:52 | 2021-09-17 05:30 |
| GHSA-C77F-4RGJ-JFR4 CVE-2021-39391 | Cross-site Scripting in Beego | 中危 | Gogithub.com/beego/beego/v2 | 已审查 | 2021-09-16 04:23 | 2023-12-08 07:44 |
| GHSA-5VP3-V4HC-GX76 CVE-2021-41264 | UUPSUpgradeable vulnerability in @openzeppelin/contracts | 严重 | npm@openzeppelin/contracts+1 | 已审查 | 2021-09-16 04:23 | 2021-11-17 05:44 |
| GHSA-Q4H9-46XG-M3X9 | UUPSUpgradeable vulnerability in @openzeppelin/contracts-upgradeable | 严重 | npm@openzeppelin/contracts-upgradeable | 已审查 | 2021-09-16 04:22 | 2021-09-15 06:17 |
| GHSA-2GHC-6V89-PW9J CVE-2021-3666 | body-parser-xml vulnerable to Prototype Pollution | 高危 | npmbody-parser-xml | 已审查 | 2021-09-15 04:25 | 2022-08-11 07:37 |
| GHSA-2RH5-JVGX-PGW3 | Any storage file can be downloaded from p.sh if full server path is known | 高危 | Packagistezsystems/ezplatform | 已审查 | 2021-09-15 04:25 | 2021-09-15 02:35 |
| GHSA-GQCF-83RQ-GPFR | Any storage file can be downloaded from p.sh if full server path is known | 高危 | Packagistibexa/post-install | 已审查 | 2021-09-15 04:24 | 2021-09-15 02:35 |
| GHSA-23CM-X6J7-6HQ3 CVE-2021-40823 | matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver | 中危 | npmmatrix-js-sdk | 已审查 | 2021-09-15 04:24 | 2023-08-09 03:58 |
| GHSA-CQQH-49MX-FQ63 CVE-2021-3645 | merge vulnerable to Prototype Pollution | 严重 | npm@viking04/merge | 已审查 | 2021-09-14 04:16 | 2022-08-11 07:45 |
| GHSA-4JQC-8M5R-9RPR CVE-2021-23440 | Prototype Pollution in set-value | 高危 | npmset-value+1 | 已审查 | 2021-09-14 04:09 | 2023-11-04 04:24 |
| GHSA-99PX-7724-484V CVE-2021-40146 | Remote Code Execution in Any23 | 严重 | Mavenorg.apache.any23:apache-any23 | 已审查 | 2021-09-14 04:06 | 2021-09-24 21:10 |
| GHSA-838R-HVWH-24H8 CVE-2021-38555 | XML Injection in Any23 | 严重 | Mavenorg.apache.any23:apache-any23 | 已审查 | 2021-09-14 04:06 | 2021-09-24 21:10 |
| GHSA-MWGJ-7X7J-6966 CVE-2021-24040 | Deserialization of Untrusted Data in ParlAI | 中危 | PyPIparlai | 已审查 | 2021-09-14 04:06 | 2021-09-14 03:29 |