检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-V596-FWHQ-8X48 CVE-2018-1199 | Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core | 中危 | Mavenorg.springframework:spring-core+1 | 已审查 | 2018-10-18 04:01 | 2024-03-15 23:51 |
| GHSA-MH7G-99W9-XPJM CVE-2017-12629 |
当前筛选结果 35,190 条 · 时间按北京时间显示
Remote code execution occurs in Apache Solr |
| 严重 |
Mavenorg.apache.solr:solr-core |
| 已审查 |
| 2018-10-18 03:56 |
| 2024-04-13 05:09 |
| GHSA-RC9V-H28F-JCMF CVE-2018-8010 | There is a XML external entity expansion (XXE) vulnerability in Apache Solr config files | 中危 | Mavenorg.apache.solr:solr-core | 已审查 | 2018-10-18 03:56 | 2024-03-05 06:58 |
| GHSA-3PPH-2595-CGFH CVE-2018-1308 | There is a XML external entity expansion (XXE) vulnerability in Apache Solr | 高危 | Mavenorg.apache.solr:solr-core | 已审查 | 2018-10-18 03:55 | 2024-03-05 04:32 |
| GHSA-7PX3-6F6G-HXCJ CVE-2018-8026 | XML external entity expansion in org.apache.solr:solr-core | 中危 | Mavenorg.apache.solr:solr-core | 已审查 | 2018-10-18 03:55 | 2024-03-05 07:38 |
| GHSA-RHQ2-2574-78MC CVE-2018-17297 | Unzip function in ZipUtil.java in Hutool allows remote attackers to overwrite arbitrary files via directory traversal | 高危 | Mavencn.hutool:hutool-all+2 | 已审查 | 2018-10-18 03:54 | 2022-04-27 22:42 |
| GHSA-C8CC-P3J7-4C7F CVE-2018-8023 | Moderate severity vulnerability that affects org.apache.mesos:mesos | 中危 | Mavenorg.apache.mesos:mesos | 已审查 | 2018-10-18 03:54 | 2021-09-09 05:43 |
| GHSA-4R64-WF76-C53P CVE-2018-17785 | In blynk-server a Directory Traversal exists | 高危 | Mavencom.github.blynkkk:blynk-server | 已审查 | 2018-10-18 03:52 | 2022-04-27 22:26 |
| GHSA-Q35P-CHC6-7X57 CVE-2018-1332 | Moderate severity vulnerability that affects org.apache.storm:storm-core | 中危 | Mavenorg.apache.storm:storm-core | 已审查 | 2018-10-18 03:48 | 2021-09-17 03:20 |
| GHSA-P8JX-X2VW-WM33 CVE-2018-1331 | Code execution in org.apache.storm:storm-core | 高危 | Mavenorg.apache.storm:storm-core | 已审查 | 2018-10-18 03:48 | 2024-04-20 03:46 |
| GHSA-X825-RJWW-2245 CVE-2017-9799 | Apache Storm it is possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user | 高危 | Mavenorg.apache.storm:storm-core | 已审查 | 2018-10-18 02:30 | 2022-04-27 22:25 |
| GHSA-6FVX-R7HX-3VH6 CVE-2018-15531 | JavaMelody has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java. | 严重 | Mavennet.bull.javamelody:javamelody-core | 已审查 | 2018-10-18 02:28 | 2022-04-27 22:25 |
| GHSA-GX96-VGF7-HWFG CVE-2018-11797 | In Apache PDFBox a carefully crafted PDF file can trigger an extremely long running computation | 中危 | Mavenorg.apache.pdfbox:pdfbox | 已审查 | 2018-10-18 02:22 | 2022-04-27 22:23 |
| GHSA-4C32-XMGJ-2G98 CVE-2016-2175 | High severity vulnerability that affects org.apache.pdfbox:pdfbox | 高危 | Mavenorg.apache.pdfbox:pdfbox | 已审查 | 2018-10-18 02:22 | 2021-09-01 22:11 |
| GHSA-H5F5-RJ4R-42F6 CVE-2018-18389 | Incorrect access control in Neo4j Enterprise Database Server via LDAP authentication | 严重 | Mavenorg.neo4j:neo4j-enterprise | 已审查 | 2018-10-18 01:31 | 2022-04-27 22:23 |
| GHSA-5Q8M-MQMX-PXP9 CVE-2018-1274 | Spring Data Commons contain a property path parser vulnerability caused by unlimited resource allocation | 高危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2018-10-18 01:23 | 2024-03-05 04:01 |
| GHSA-M929-7FR6-CVJG CVE-2018-1259 | Spring Data Commons, used in combination with XMLBeam, contains a property binder vulnerability caused by improper restriction of XML external entity references | 高危 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2018-10-18 01:23 | 2022-04-27 21:58 |
| GHSA-4FQ3-MR56-CG6R CVE-2018-1273 | Spring Data Commons remote code injection vulnerability | 严重 | Mavenorg.springframework.data:spring-data-commons | 已审查 | 2018-10-18 01:23 | 2024-03-20 22:20 |
| GHSA-FFJH-FJGG-MFPQ CVE-2017-7677 | Moderate severity vulnerability that affects org.apache.ranger:ranger | 中危 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:22 | 2021-09-11 02:07 |
| GHSA-758M-6G3Q-G3HH CVE-2017-7676 | Policy resource matcher in Apache Ranger before 0.7.1 ignores characters after '' wildcard character | 严重 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:22 | 2022-04-27 21:54 |
| GHSA-C99H-FGQM-6679 CVE-2018-11778 | UnixAuthenticationService in Apache Ranger was updated to correctly handle user input to avoid Stack-based buffer overflow | 高危 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:22 | 2022-04-27 21:52 |
| GHSA-XV7X-X6WR-XX7G CVE-2016-8746 | Apache Ranger policy engine incorrectly matches paths in certain conditions | 中危 | Mavenorg.apache.ranger:ranger-plugins-common | 已审查 | 2018-10-18 01:22 | 2023-11-21 19:56 |
| GHSA-V7MF-QGXF-QMVF CVE-2016-8751 | Apache Ranger admin users can store some arbitrary javascript code to be executed when normal users login and access policies | 中危 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:21 | 2022-04-27 21:49 |
| GHSA-VHXC-8JJQ-859J CVE-2016-6815 | Moderate severity vulnerability that affects org.apache.ranger:ranger | 中危 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:21 | 2021-09-21 06:05 |
| GHSA-RF7Q-XQM3-6923 CVE-2016-5395 | Apache Ranger allows remote authenticated administrators to inject arbitrary web script or HTML | 中危 | Mavenorg.apache.ranger:ranger | 已审查 | 2018-10-18 01:21 | 2022-04-27 21:48 |