检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WQ3R-JWRQ-XG6W | Canceling of orders not related to the logged-in user | 中危 | Packagistshopware/core+1 | 已审查 | 2021-06-29 00:57 | 2021-06-25 02:04 |
| GHSA-C99R-67X4-WHJ6 CVE-2021-33604 | Reflected cross-site scripting in development mode handler in Vaadin 14, 15-19 |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 低危 |
Mavencom.vaadin:vaadin-bom |
| 已审查 |
| 2021-06-29 00:56 |
| 2021-10-06 01:29 |
| GHSA-QRG9-F472-QWFM CVE-2021-31412 | Possible route enumeration in production mode via RouteNotFoundError view in Vaadin 10, 11-14, and 15-19 | 中危 | Mavencom.vaadin:vaadin-bom | 已审查 | 2021-06-29 00:55 | 2021-06-25 03:46 |
| GHSA-8VFW-V2JV-9HWC | Reflected cross-site scripting in development mode handler in Vaadin | 低危 | Mavencom.vaadin:flow-server | 已审查 | 2021-06-29 00:52 | 2021-06-25 03:39 |
| GHSA-954C-JJX6-CXV7 CVE-2021-32702 | Reflected XSS from the callback handler's error query parameter | 高危 | npm@auth0/nextjs-auth0 | 已审查 | 2021-06-29 00:46 | 2021-06-29 03:06 |
| GHSA-2JX8-V4HV-GX3H CVE-2020-12642 | XXE vulnerability in Launch import | 高危 | Mavencom.epam.reportportal:service-api | 已审查 | 2021-06-29 00:45 | 2021-10-06 01:29 |
| GHSA-24WF-7VF2-PV59 CVE-2021-29620 | XXE vulnerability on Launch import with externally-defined DTD file | 高危 | Mavencom.epam.reportportal:service-api | 已审查 | 2021-06-29 00:38 | 2021-06-25 21:06 |
| GHSA-35QP-XQ9F-2RJX CVE-2021-3283 | Improper Privilege Management in HashiCorp Nomad | 高危 | Gogithub.com/hashicorp/nomad | 已审查 | 2021-06-25 04:28 | 2021-05-13 05:38 |
| GHSA-VF6Q-9F2F-MWHV CVE-2021-32575 | Improper network isolation in Hashicorp Nomad | 中危 | Gogithub.com/hashicorp/nomad | 已审查 | 2021-06-25 04:28 | 2021-06-24 02:01 |
| GHSA-VFVF-6GX5-MQV6 CVE-2021-32701 | Incorrect Authorization in ORY Oathkeeper | 高危 | Gogithub.com/ory/oathkeeper | 已审查 | 2021-06-25 04:16 | 2021-06-24 04:38 |
| GHSA-HJ56-84JW-67H6 CVE-2021-32823 | Potential Denial-of-Service in bindata | 中危 | RubyGemsbindata | 已审查 | 2021-06-24 07:42 | 2024-11-19 00:26 |
| GHSA-M6CP-VXJX-65J6 CVE-2021-34428 | SessionListener can prevent a session from being invalidated breaking logout | 低危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2021-06-24 04:23 | 2022-02-09 05:21 |
| GHSA-C38G-469G-CMGX CVE-2021-21303 | Improper Neutralization of Special Elements in Output in helm.sh/helm/v3 | 中危 | Gohelm.sh/helm/v3 | 已审查 | 2021-06-24 02:14 | 2024-06-01 00:48 |
| GHSA-QQ3J-XP49-J73F CVE-2020-4053 | Plugin archive directory traversal in Helm | 低危 | Gohelm.sh/helm/v3 | 已审查 | 2021-06-24 02:14 | 2024-02-14 00:33 |
| GHSA-7JR6-PRV4-5WF5 | Duplicate Advisory: Helm passes repository credentials to alternate domain 已撤回 | 中危 | Gohelm.sh/helm/v3 | 已审查 | 2021-06-24 02:14 | 2024-05-21 05:26 |
| GHSA-56HP-XQP3-W2JF CVE-2021-32690 | Helm passes repository credentials to alternate domain | 中危 | Gohelm.sh/helm/v3 | 已审查 | 2021-06-24 02:14 | 2024-05-21 05:31 |
| GHSA-6RG3-8H8X-5XFV | Unchecked hostname resolution could allow access to local network resources by users outside the local network | 中危 | Gogithub.com/pterodactyl/wings | 已审查 | 2021-06-24 02:04 | 2021-10-06 01:24 |
| GHSA-JJ6M-R8JC-2GP7 CVE-2021-32699 | Asymmetric Resource Consumption (Amplification) in Docker containers created by Wings | 中危 | Gogithub.com/pterodactyl/wings | 已审查 | 2021-06-24 02:03 | 2022-10-26 04:24 |
| GHSA-CJJC-XP8V-855W CVE-2020-7919 | Helm uses crypto package vulnerable to panic from malformed X.509 certificate | 高危 | Gogithub.com/helm/helm+2 | 已审查 | 2021-06-24 02:02 | 2024-06-01 01:06 |
| GHSA-QVP4-RPMR-XWRR | Possible bypass of token claim validation when OAuth2 Introspection caching is enabled | 高危 | Gogithub.com/ory/oathkeeper | 已审查 | 2021-06-24 02:00 | 2021-06-23 04:50 |
| GHSA-9QQ2-XHMC-H9QR CVE-2018-20321 | Access Control Bypass | 中危 | Gogithub.com/rancher/rancher | 已审查 | 2021-06-24 01:57 | 2022-04-26 04:20 |
| GHSA-H395-QCRW-5VMQ CVE-2020-28483 | Inconsistent Interpretation of HTTP Requests in github.com/gin-gonic/gin | 高危 | Gogithub.com/gin-gonic/gin | 已审查 | 2021-06-24 01:53 | 2024-05-21 03:29 |
| GHSA-W942-GW6M-P62C CVE-2020-35380 | Denial of service in GJSON | 高危 | Gogithub.com/tidwall/gjson | 已审查 | 2021-06-24 01:53 | 2024-05-21 03:27 |
| GHSA-HWQM-X785-QH8P CVE-2020-12797 | Incorrect Permission Assignment for Critical Resource in Hashicorp Consul | 中危 | Gogithub.com/hashicorp/consul | 已审查 | 2021-06-24 01:52 | 2023-10-02 23:09 |
| GHSA-4HQ8-GMXX-H6W9 CVE-2020-27846 | XML Processing error in github.com/crewjam/saml | 严重 | Gogithub.com/crewjam/saml | 已审查 | 2021-06-24 01:29 | 2025-09-20 01:41 |