检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-VF2H-7X3W-97FR CVE-2026-53474 | Openshift Migration Advisor: Improper input sanitization allows specially crafted RVTools .xlsx files to include malicious SQL commands | 严重 | Gogithub.com/kubev2v/migration-planner | 已审查 | 2026-06-10 23:31 | 2026-08-15 03:19 |
| GHSA-V5M8-5455-QW2X CVE-2026-53470 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs |
| 严重 |
Gogithub.com/kubev2v/migration-planner |
| 已审查 |
| 2026-06-10 23:31 |
| 2026-08-14 23:37 |
| GHSA-8G5P-JXP9-457C CVE-2026-53475 | Assisted Migration Agent: Hardcoded insecure Transport Layer Security (TLS) connections during vCenter communication | 严重 | Gogithub.com/kubev2v/assisted-migration-agent | 已审查 | 2026-06-10 23:31 | 2026-08-15 03:20 |
| GHSA-7J4W-X8X8-5MVG CVE-2026-53476 | Assisted Migration Agent: Path traversal in gzipped tarball handling enables arbitrary file write and remote code execution | 严重 | Gogithub.com/kubev2v/assisted-migration-agent | 已审查 | 2026-06-10 23:31 | 2026-08-15 03:21 |
| GHSA-6XVF-9742-48W2 CVE-2026-53469 | Openshift Migration Advisor lacks proper authorization and filtering for its DELETE /api/v1/sources API | 严重 | Gogithub.com/kubev2v/migration-planner | 已审查 | 2026-06-10 23:31 | 2026-08-14 04:51 |
| GHSA-2FQW-7C6R-2CQ6 CVE-2026-53471 | Openshift Migration Advisor agent-API fails to validate JWT source_id claim, allowing cross-tenant data manipulation | 严重 | Gogithub.com/kubev2v/migration-planner | 已审查 | 2026-06-10 23:31 | 2026-08-14 23:38 |
| GHSA-MW82-XCG6-GX79 CVE-2026-53438 | Jenkins: Missing permission check allows unauthorized cancellation of queue items | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-14 04:49 |
| GHSA-M6WV-WH8G-64XC CVE-2026-53442 | Jenkins does not encrypt secrets from POST config.xml submissions before storing them in job configurations | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-14 04:51 |
| GHSA-G2XQ-2V27-4RH3 CVE-2026-53435 | Jenkins arbitrary type deserialization from attacker-controlled config.xml allows remote code execution and user impersonation | 高危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-27 23:31 |
| GHSA-G28P-6MCC-V4RV CVE-2026-53439 | Jenkins exposes other users' timezone and view names to users with Overall/Read permission | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-14 04:50 |
| GHSA-93QH-VWRM-C5PW CVE-2026-53441 | Jenkins: Stored XSS vulnerability in node offline cause description | 高危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-06-13 06:15 |
| GHSA-92M7-4FPW-2WXM CVE-2026-53440 | Jenkins: Open Redirect phishing attacks possible via "from" parameter in "Delegate to servlet container" | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-14 04:50 |
| GHSA-463R-5M89-4XFR CVE-2026-53437 | Jenkins Open Redirect Through Newline/Tab Characters in Redirect URL | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-27 23:31 |
| GHSA-3RQH-HCH3-JHPC CVE-2026-53436 | Jenkins Open Redirect via Relative Path Segments in Post-Login Redirect URL | 中危 | Mavenorg.jenkins-ci.main:jenkins-core | 已审查 | 2026-06-10 23:31 | 2026-08-14 02:21 |
| GHSA-W3RX-R6R6-PGPR CVE-2025-71330 | image-size: ICNS parser allows denial of service through an infinite loop | 高危 | npmimage-size | 已审查 | 2026-06-10 23:31 | 2026-08-08 04:55 |
| GHSA-5P2G-FCMC-QVQQ CVE-2025-71329 | image-size: JXL and HEIF parsers allow denial of service through infinite loops | 高危 | npmimage-size | 已审查 | 2026-06-10 23:31 | 2026-08-08 04:54 |
| GHSA-VRMH-5MMX-HJWX CVE-2026-49397 | Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data | 中危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-10 21:39 | 2026-06-27 05:29 |
| GHSA-8QHJ-4F8C-J8QG CVE-2026-49396 | Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents | 高危 | Gogithub.com/nezhahq/nezha | 已审查 | 2026-06-10 21:39 | 2026-06-27 05:28 |
| GHSA-MQQ6-462X-JXMM CVE-2026-48031 | Go Restful API Boilerplate: Hardcoded JWT Secret "random" Allows Token Forgery | 严重 | Gogithub.com/dhax/go-base | 已审查 | 2026-06-10 21:39 | 2026-06-10 21:39 |
| GHSA-5G86-85RP-F9HX CVE-2026-48051 | Papra HTTP redirect bypass can lead to SSRF via webhook delivery system | 低危 | npm@papra/webhooks | 已审查 | 2026-06-10 21:39 | 2026-06-10 21:39 |
| GHSA-CJ8G-PRCM-MFG5 CVE-2026-48037 | @hulumi/baseline: AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture | 中危 | npm@hulumi/baseline | 已审查 | 2026-06-10 21:38 | 2026-06-10 21:38 |
| GHSA-32G3-35G9-WC9G CVE-2026-48036 | @hulumi/drift: Drift classifier fails open on adapter errors and over-promotes Mixed verdicts | 高危 | npm@hulumi/drift | 已审查 | 2026-06-10 21:38 | 2026-06-10 21:38 |
| GHSA-2MXR-P26X-MJ73 CVE-2026-48035 | @hulumi/baseline: AccountFoundation audit-delivery S3 bucket could be silently weakened | 高危 | npm@hulumi/baseline | 已审查 | 2026-06-10 21:38 | 2026-06-10 21:38 |
| GHSA-9VC9-4JV3-RF86 CVE-2026-48034 | @hulumi/policies has a HULUMI-H5 bypass via decoy sibling resources targeting a different bucket | 高危 | npm@hulumi/policies | 已审查 | 2026-06-10 21:38 | 2026-06-10 21:38 |
| GHSA-RHGJ-6G2C-FRMM CVE-2026-48033 | @hulumi/policies bypasses policy packs with a forged Pulumi-URN logical name | 高危 | npm@hulumi/policies | 已审查 | 2026-06-10 21:37 | 2026-06-10 21:37 |