检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9R2W-394V-53QC CVE-2021-37701 | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links | 高危 | npmtar | 已审查 | 2021-09-01 00:05 | 2021-09-01 00:01 |
| GHSA-QQ89-HQ3F-393P CVE-2021-37712 | Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmtar |
| 已审查 |
| 2021-09-01 00:05 |
| 2021-09-01 00:02 |
| GHSA-5955-9WPR-37JH CVE-2021-37713 | Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization | 高危 | npmtar | 已审查 | 2021-09-01 00:05 | 2021-09-01 00:02 |
| GHSA-2H3H-Q99F-3FHC CVE-2021-39134 | @npmcli/arborist vulnerable to UNIX Symbolic Link (Symlink) Following | 高危 | npm@npmcli/arborist | 已审查 | 2021-09-01 00:04 | 2022-08-16 04:08 |
| GHSA-GMW6-94GG-2RC2 CVE-2021-39135 | UNIX Symbolic Link (Symlink) Following in @npmcli/arborist | 高危 | npm@npmcli/arborist | 已审查 | 2021-09-01 00:03 | 2022-06-18 04:51 |
| GHSA-34JQ-548X-M2X9 CVE-2021-38623 | Improper Resource Shutdown or Release in TYPO3 extension | 高危 | Packagistwebcoast/deferred-image-processing | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:19 |
| GHSA-23FQ-Q7HC-993R CVE-2021-38553 | HashiCorp Vault underlying database had excessively broad filesystem permissions from v1.4.0 until v1.8.0 | 严重 | Gogithub.com/hashicorp/vault | 已审查 | 2021-08-31 01:22 | 2022-08-12 05:57 |
| GHSA-6239-28C2-9MRM CVE-2021-38554 | Improper Removal of Sensitive Information Before Storage or Transfer in HashiCorp Vault | 中危 | Gogithub.com/hashicorp/vault | 已审查 | 2021-08-31 01:22 | 2022-08-04 19:22 |
| GHSA-JJ8R-P9F5-FMVV CVE-2021-36785 | Cross-site Scripting in TYPO3 extension | 中危 | Packagistminiorange/miniorange-saml | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:07 |
| GHSA-H5Q8-5697-9P9H CVE-2020-22403 | Cross-Site Request Forgery in express-cart | 高危 | npmexpress-cart | 已审查 | 2021-08-31 01:22 | 2021-08-31 01:02 |
| GHSA-5PH6-QQ5X-7JWC CVE-2021-32783 | ExternalName Services can be used to gain access to Envoy's admin interface | 高危 | Gogithub.com/projectcontour/contour | 已审查 | 2021-08-31 01:22 | 2021-08-31 00:53 |
| GHSA-26RR-V2J2-25FH CVE-2021-32758 | Layout XML Arbitrary Code Fix | 高危 | Packagistopenmage/magento-lts | 已审查 | 2021-08-31 01:20 | 2021-08-31 00:42 |
| GHSA-XM9F-VXMX-4M58 CVE-2021-32759 | Data Flow Sanitation Issue Fix | 高危 | Packagistopenmage/magento-lts | 已审查 | 2021-08-31 01:20 | 2021-08-31 00:42 |
| GHSA-M6H2-JX9V-58W6 CVE-2021-35936 | Missing Authorization in Apache Airflow | 中危 | PyPIapache-airflow | 已审查 | 2021-08-31 00:25 | 2024-09-12 03:51 |
| GHSA-HF6P-4RV2-9QRP CVE-2021-23423 | Path Traversal in bikshed | 中危 | PyPIbikeshed | 已审查 | 2021-08-31 00:25 | 2024-09-05 05:13 |
| GHSA-87CJ-PX37-RC3X CVE-2021-23422 | OS Command Injection in bikeshed | 高危 | PyPIbikeshed | 已审查 | 2021-08-31 00:25 | 2024-09-05 05:12 |
| GHSA-F2RP-J8HV-G5GX CVE-2021-38713 | Cross-site scripting in imgURL | 中危 | Packagisthelloxz/imgurl | 已审查 | 2021-08-31 00:25 | 2021-08-27 00:24 |
| GHSA-4Q2R-QXP6-H5J6 CVE-2020-18705 | Improper Restriction of XML External Entity Reference in Quokka | 严重 | PyPIquokka | 已审查 | 2021-08-31 00:25 | 2024-10-17 05:33 |
| GHSA-V3CG-H3F6-2242 CVE-2021-32827 | Injection in MockServer | 中危 | Mavenorg.mock-server:mockserver | 已审查 | 2021-08-31 00:24 | 2022-02-09 05:01 |
| GHSA-98HV-QFF3-8793 CVE-2020-18704 | Unrestricted Upload of File with Dangerous Type in django-widgy | 严重 | PyPIdjango-widgy | 已审查 | 2021-08-31 00:24 | 2024-09-17 06:06 |
| GHSA-3XG5-6C3J-VP8X CVE-2020-18703 | Improper Restriction of XML External Entity Reference in Quokka | 严重 | PyPIquokka | 已审查 | 2021-08-31 00:23 | 2024-10-17 05:28 |
| GHSA-5M69-3CHG-6F8M CVE-2020-18702 | Cross Site Scripting (XSS) in Quokka | 中危 | PyPIquokka | 已审查 | 2021-08-31 00:23 | 2024-10-25 05:55 |
| GHSA-CPV8-6XGR-RMF6 CVE-2021-25955 | Dolibarr Cross-site Scripting vulnerability | 严重 | Packagistdolibarr/dolibarr | 已审查 | 2021-08-31 00:22 | 2022-08-11 07:57 |
| GHSA-6GVC-4JVJ-PWQ4 | Duplicate Advisory: Use after free in libpulse-binding 已撤回 | 中危 | crates.iolibpulse-binding | 已审查 | 2021-08-31 00:22 | 2026-01-23 06:35 |
| GHSA-F8PV-X7H8-687V CVE-2020-19709 | Cross-site scripting in feehicms | 中危 | Packagistfeehi/feehicms | 已审查 | 2021-08-31 00:22 | 2021-09-03 02:50 |