检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-65RM-H285-5CC5 CVE-2019-12855 | Improper Certificate Validation in Twisted | 严重 | PyPITwisted | 已审查 | 2019-08-16 22:02 | 2024-11-26 03:24 |
| GHSA-FPQP-V323-44XV CVE-2019-12397 | Cross-site scripting in Apache Ranger |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 中危 |
Mavenorg.apache.ranger:ranger |
| 已审查 |
| 2019-08-16 22:01 |
| 2021-08-18 04:42 |
| GHSA-6R97-CJ55-9HRQ CVE-2019-14234 | SQL Injection in Django | 严重 | PyPIDjango | 已审查 | 2019-08-16 22:00 | 2024-09-21 00:08 |
| GHSA-FP5J-3FPF-MHJ5 CVE-2019-10099 | Sensitive data written to disk unencrypted in Spark | 高危 | Mavenorg.apache.spark:spark-core_2.11+1 | 已审查 | 2019-08-08 23:18 | 2024-10-25 05:48 |
| GHSA-MFWH-GQX8-C787 CVE-2019-10088 | Allocation of Resources Without Limits or Throttling in Apache Tika | 高危 | Mavenorg.apache.tika:tika-core | 已审查 | 2019-08-06 09:43 | 2021-05-06 06:58 |
| GHSA-4MQ5-MJ59-QQ9C CVE-2019-10093 | Allocation of Resources Without Limits or Throttling in Apache Tika | 中危 | Mavenorg.apache.tika:tika-parsers | 已审查 | 2019-08-06 09:43 | 2021-05-06 06:55 |
| GHSA-MM7M-XG4H-6M52 CVE-2019-10094 | Allocation of Resources Without Limits or Throttling in Apache Tika | 高危 | Mavenorg.apache.tika:tika-core | 已审查 | 2019-08-06 09:43 | 2021-05-06 06:59 |
| GHSA-H5JV-4P7W-64JG CVE-2019-14233 | Django Denial-of-service in strip_tags() | 高危 | PyPIDjango | 已审查 | 2019-08-06 09:43 | 2024-09-21 00:25 |
| GHSA-V9QG-3J8P-R63V CVE-2019-14235 | Uncontrolled Recursion in Django | 高危 | PyPIDjango | 已审查 | 2019-08-06 09:43 | 2024-09-21 00:09 |
| GHSA-C4QH-4VGV-QC6G CVE-2019-14232 | Django Denial-of-service in django.utils.text.Truncator | 高危 | PyPIDjango | 已审查 | 2019-08-06 09:43 | 2024-09-21 00:15 |
| GHSA-W69W-JVC7-WJGV CVE-2019-10184 | Undertow Missing Authorization when requesting a protected directory without trailing slash | 高危 | Mavenio.undertow:undertow-servlet | 已审查 | 2019-08-02 03:18 | 2023-09-25 18:52 |
| GHSA-GWP4-HFV6-P7HW CVE-2019-14439 | Deserialization of untrusted data in FasterXML jackson-databind | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2019-08-02 03:18 | 2023-11-28 07:03 |
| GHSA-6FPP-RGJ9-8RWC CVE-2019-14379 | Deserialization of untrusted data in FasterXML jackson-databind | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2019-08-02 03:18 | 2023-09-14 01:18 |
| GHSA-25PC-85QF-6J69 CVE-2018-11779 | Deserialization of Untrusted Data in Apache Storm | 严重 | Mavenorg.apache.storm:storm-kafka+1 | 已审查 | 2019-08-02 03:17 | 2021-08-18 04:24 |
| GHSA-JVPP-HXJJ-5CCC CVE-2015-7559 | Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ | 中危 | Mavenorg.apache.activemq:activemq-client | 已审查 | 2019-08-02 03:17 | 2023-12-21 04:40 |
| GHSA-3GM7-V7VW-866C CVE-2019-0193 | XML External Entity (XXE) Injection in Apache Solr | 高危 | Mavenorg.apache.solr:solr-core | 已审查 | 2019-08-02 03:17 | 2025-10-23 01:44 |
| GHSA-GRGM-PPH5-J5H7 CVE-2019-10156 | Exposure of Sensitive Information to an Unauthorized Actor in ansible | 中危 | PyPIansible | 已审查 | 2019-07-31 12:22 | 2024-09-05 04:45 |
| GHSA-7J93-2H6R-HM49 CVE-2019-5458 | Cross-Site Scripting in http-file-server | 中危 | npmhttp-file-server | 已审查 | 2019-07-31 12:22 | 2023-02-01 17:19 |
| GHSA-J657-59RV-QWM6 CVE-2019-5457 | Cross-Site Scripting in min-http-server | 中危 | npmmin-http-server | 已审查 | 2019-07-31 12:22 | 2022-12-03 12:03 |
| GHSA-WQFC-CR59-H64P CVE-2019-5448 | Missing Encryption of Sensitive Data in yarn | 高危 | npmyarn | 已审查 | 2019-07-31 12:22 | 2021-08-18 03:40 |
| GHSA-QPXP-5J56-GG3X CVE-2018-20857 | samlr XML nodes comment attack | 高危 | RubyGemssamlr | 已审查 | 2019-07-31 12:22 | 2023-08-09 00:12 |
| GHSA-RQP5-PG7W-832P CVE-2019-14281 | datagrid contains code Injection backdoor | 严重 | RubyGemsdatagrid | 已审查 | 2019-07-31 12:21 | 2023-08-26 05:06 |
| GHSA-WG6J-R28M-7293 CVE-2019-14282 | Code backdoor in simple_captcha2 | 严重 | RubyGemssimple_captcha2 | 已审查 | 2019-07-31 12:21 | 2023-08-28 21:34 |
| GHSA-J3JP-GVR5-7HWQ CVE-2019-13611 | python-engineio vulnerable to Cross-Site Request Forgery (CSRF) | 高危 | PyPIpython-engineio | 已审查 | 2019-07-31 04:47 | 2024-10-26 04:48 |
| GHSA-HF4P-JM7R-VJJJ CVE-2018-15890 | Deserialization of Untrusted Data in EthereumJ | 严重 | Mavenorg.ethereum:ethereumj-core | 已审查 | 2019-07-27 00:10 | 2021-08-18 03:40 |