检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-923P-FR2C-G5M2 CVE-2020-1739 | Exposure of Sensitive Information to an Unauthorized Actor in Ansible | 低危 | PyPIansible | 已审查 | 2021-04-08 04:30 | 2024-09-07 01:53 |
| GHSA-GG2G-M5WC-VCCQ CVE-2021-21423 | Rebuild-bot workflow may allow unauthorised repository modifications |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 高危 |
npmprojen |
| 已审查 |
| 2021-04-07 02:36 |
| 2024-10-22 04:05 |
| GHSA-PRMC-5V5W-C465 | Client TLS credentials sent raw to server in npm package nats | 严重 | npmnats | 已审查 | 2021-04-07 01:32 | 2021-04-01 02:09 |
| GHSA-J6QJ-J888-VVGQ CVE-2021-28163 | Directory exposure in jetty | 低危 | Mavenorg.eclipse.jetty:jetty-deploy | 已审查 | 2021-04-07 01:32 | 2022-04-22 23:49 |
| GHSA-26VR-8J45-3R4W CVE-2021-28165 | Jetty vulnerable to incorrect handling of invalid large TLS frame, exhausting CPU resources | 高危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2021-04-07 01:31 | 2022-08-11 07:33 |
| GHSA-V7FF-8WCX-GMC5 CVE-2021-28164 | Authorization Before Parsing and Canonicalization in jetty | 中危 | Mavenorg.eclipse.jetty:jetty-webapp | 已审查 | 2021-04-07 01:31 | 2022-04-18 00:45 |
| GHSA-JFF2-QJW8-5476 CVE-2021-21388 | Command Injection Vulnerability in systeminformation | 高危 | npmsysteminformation | 已审查 | 2021-04-07 01:30 | 2021-04-30 01:22 |
| GHSA-XW22-WV29-3299 CVE-2021-21421 | ApiKey secret could be revelated on network issue | 高危 | npmnode-etsy-client | 已审查 | 2021-04-07 01:29 | 2021-04-03 01:05 |
| GHSA-58C7-PX5V-82HH CVE-2021-21416 | Potential sensitive information disclosed in error reports | 低危 | PyPIdjango-registration | 已审查 | 2021-04-07 01:28 | 2024-09-17 05:29 |
| GHSA-3RH3-WFR4-76MJ CVE-2021-21391 | Regular expression Denial of Service in multiple packages | 中危 | npm@ckeditor/ckeditor5-engine+7 | 已审查 | 2021-04-07 01:28 | 2021-05-01 01:30 |
| GHSA-PXCC-HJ8W-FMM7 CVE-2021-21414 | Command injection vulnerability in @prisma/sdk in getPackedPackage function | 高危 | npm@prisma/sdk | 已审查 | 2021-04-07 01:25 | 2021-04-01 02:00 |
| GHSA-VM67-7VMG-66VM CVE-2021-23348 | Arbitrary Command Injection in portprocesses | 中危 | npmportprocesses | 已审查 | 2021-04-07 01:24 | 2021-04-01 01:50 |
| GHSA-VWFX-HH3W-FJ99 CVE-2021-21418 | Potential XSS injection in the newsletter conditions field | 中危 | Packagistprestashop/ps_emailsubscription | 已审查 | 2021-04-07 01:24 | 2021-04-01 01:35 |
| GHSA-MMHJ-4W6J-76H7 CVE-2021-21413 | Misuse of `Reference` and other transferable APIs may lead to access to nodejs isolate | 高危 | npmisolated-vm | 已审查 | 2021-04-07 01:22 | 2021-03-31 06:27 |
| GHSA-RJ44-GPJC-29R7 CVE-2021-21412 | [thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values | 中危 | npm@thi.ng/egf | 已审查 | 2021-04-07 01:22 | 2021-03-31 04:20 |
| GHSA-W3HJ-WR2Q-X83G CVE-2024-23688 | Discovery uses the same AES/GCM Nonce throughout the session | 低危 | Maventech.pegasys.discovery:discovery | 已审查 | 2021-04-07 01:22 | 2025-12-02 09:28 |
| GHSA-4HJQ-422Q-4VPX CVE-2021-27908 | Mautic vulnerable to secret data exfiltration via symfony parameters | 中危 | Packagistmautic/core | 已审查 | 2021-04-07 01:20 | 2024-02-05 19:00 |
| GHSA-F4JH-WW96-9H9J CVE-2021-28100 | Netflix/Priam: Temporary Directory Information Disclosure | 中危 | Mavencom.netflix.priam:priam | 已审查 | 2021-03-31 00:23 | 2021-03-31 00:22 |
| GHSA-F256-J965-7F32 CVE-2021-21409 | Possible request smuggling in HTTP/2 due missing validation of content-length | 中危 | Mavenio.netty:netty+2 | 已审查 | 2021-03-30 23:10 | 2022-02-09 05:31 |
| GHSA-PCH5-WHG9-QR2R CVE-2021-29418 | netmask npm package mishandles octal input data | 中危 | npmnetmask | 已审查 | 2021-03-30 05:32 | 2023-09-09 04:25 |
| GHSA-PRXJ-C66C-4GCF CVE-2019-0924 | Out-of-bounds write | 高危 | NuGetMicrosoft.ChakraCore | 已审查 | 2021-03-30 05:00 | 2021-03-19 06:02 |
| GHSA-HRMM-F4J8-8VXC CVE-2019-0922 | Out-of-bounds write | 高危 | NuGetMicrosoft.ChakraCore | 已审查 | 2021-03-30 05:00 | 2021-03-19 05:56 |
| GHSA-7423-5QFM-G648 CVE-2019-0916 | Out-of-bounds write | 高危 | NuGetMicrosoft.ChakraCore | 已审查 | 2021-03-30 05:00 | 2021-03-19 05:51 |
| GHSA-H23M-W6X5-JWR4 CVE-2019-0923 | Out-of-bounds write | 高危 | NuGetMicrosoft.ChakraCore | 已审查 | 2021-03-30 05:00 | 2021-03-19 05:55 |
| GHSA-RX34-JFF5-PH35 CVE-2019-0917 | Out-of-bounds write | 高危 | NuGetMicrosoft.ChakraCore | 已审查 | 2021-03-30 05:00 | 2021-03-19 05:48 |