检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-JJ9H-MWHQ-8VHM CVE-2016-3094 | Improper Input Validation in org.apache.qpid:qpid-broker | 中危 | Mavenorg.apache.qpid:qpid-broker | 已审查 | 2018-10-17 03:50 | 2023-05-23 05:30 |
| GHSA-Q66C-H853-GQW2 CVE-2016-4432 | AMQP 0-8, 0-9, 0-91, and 0-10 connection handling in Apache Qpid Java before 6.0.3 might allow remote attackers to bypass authentication |
当前筛选结果 35,190 条 · 时间按北京时间显示
| 严重 |
Mavenorg.apache.qpid:qpid-broker-plugins-amqp-0-8-protocol+1 |
| 已审查 |
| 2018-10-17 03:49 |
| 2023-01-18 14:20 |
| GHSA-49H4-G8P5-JGQ6 CVE-2015-5241 | Moderate severity vulnerability that affects org.apache.juddi:juddi-client | 中危 | Mavenorg.apache.juddi:juddi-client | 已审查 | 2018-10-17 03:49 | 2021-09-01 22:10 |
| GHSA-GG9M-FJ3V-R58C CVE-2017-9805 | REST Plugin in Apache Struts uses an XStreamHandler with an instance of XStream for deserialization without any type filtering | 高危 | Mavenorg.apache.struts:struts2-rest-plugin | 已审查 | 2018-10-17 03:37 | 2025-10-23 01:31 |
| GHSA-X5X7-3V85-WPC4 CVE-2017-9804 | Apache Struts allows entering a custom URL in a form field if built-in URLValidator is used | 高危 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-17 03:37 | 2024-01-05 07:26 |
| GHSA-VWXJ-6M5M-RRVH CVE-2017-9793 | The REST Plugin in Apache Struts is using an outdated XStream library | 高危 | Mavenorg.apache.struts:struts2-rest-plugin | 已审查 | 2018-10-17 03:37 | 2022-04-27 03:02 |
| GHSA-8MR5-H28G-36QX CVE-2017-9787 | Spring AOP functionality (Struts) vulnerable to DoS attack | 高危 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-17 03:37 | 2022-04-27 03:00 |
| GHSA-9GP7-JVM2-R4MX CVE-2017-7672 | Apache Struts Improper Input Validation vulnerability | 中危 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-17 03:36 | 2024-01-05 07:08 |
| GHSA-XCRM-QPP8-HCW4 CVE-2017-15707 | Moderate severity vulnerability that affects org.apache.struts:struts2-rest-plugin | 中危 | Mavenorg.apache.struts:struts2-rest-plugin | 已审查 | 2018-10-17 03:35 | 2021-09-22 06:29 |
| GHSA-8FX9-5HX8-CRHM CVE-2017-12611 | Apache Struts 2.0.1 uses an unintentional expression in a Freemarker tag instead of string literal | 严重 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-17 03:35 | 2024-01-05 05:54 |
| GHSA-38CR-2PH5-FRR9 CVE-2018-1327 | Apache Struts REST Plugin can potentially allow a DoS attack | 高危 | Mavenorg.apache.struts:struts2-rest-plugin | 已审查 | 2018-10-17 03:35 | 2024-01-06 00:06 |
| GHSA-X2RG-FMCV-CRQ5 CVE-2017-9822 | DNN (aka DotNetNuke) has Remote Code Execution via a cookie | 高危 | NuGetDotNetNuke.Core | 已审查 | 2018-10-17 03:34 | 2022-04-27 02:58 |
| GHSA-5C66-X4WM-RJFX CVE-2016-7119 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) | 中危 | NuGetDotNetNuke.Core | 已审查 | 2018-10-17 03:34 | 2022-04-27 02:58 |
| GHSA-X8F7-H444-97W4 CVE-2015-2794 | The installation wizard in DotNetNuke (DNN) allows privilege escalation | 严重 | NuGetDotNetNuke.Core | 已审查 | 2018-10-17 03:33 | 2022-04-27 02:57 |
| GHSA-V76M-F5CX-8RG4 CVE-2015-1566 | Moderate severity vulnerability that affects DotNetNuke.Core | 中危 | NuGetDotNetNuke.Core | 已审查 | 2018-10-17 03:33 | 2020-06-17 05:57 |
| GHSA-CGGJ-FVV3-CQWV CVE-2018-7489 | FasterXML jackson-databind allows unauthenticated remote code execution | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2018-10-17 01:45 | 2024-03-15 09:08 |
| GHSA-XQJ7-J8J5-F2XR CVE-2018-1000180 | Bouncy Castle has a flaw in the Low-level interface to RSA key pair generator | 高危 | Mavenorg.bouncycastle:bcprov-jdk14+2 | 已审查 | 2018-10-17 01:44 | 2025-09-13 03:26 |
| GHSA-MWCX-532G-8PQ3 CVE-2018-12538 | Access and integrity issue within Eclipse Jetty | 高危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2018-10-17 01:44 | 2022-04-27 02:56 |
| GHSA-F26X-PR96-VW86 CVE-2018-11040 | Moderate severity vulnerability that affects org.springframework:spring-core | 中危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-17 01:43 | 2024-05-15 14:25 |
| GHSA-9GCM-F4X3-8JPW CVE-2018-11039 | Spring Framework Cross Site Tracing (XST) | 中危 | Mavenorg.springframework:spring-web | 已审查 | 2018-10-17 01:35 | 2024-03-06 01:33 |
| GHSA-898J-5CC8-CMF5 CVE-2018-8008 | ZipSlip in org.apache.storm:storm-core | 中危 | Mavenorg.apache.storm:storm-core | 已审查 | 2018-10-17 01:35 | 2024-03-21 01:34 |
| GHSA-XPWP-RQ3X-X6V7 CVE-2017-0907 | Critical severity vulnerability that affects recurly-api-client | 严重 | NuGetrecurly-api-client | 已审查 | 2018-10-17 01:35 | 2020-06-17 06:03 |
| GHSA-RR3C-F55V-QHV5 CVE-2018-0764 | Denial of service vulnerability exists when .NET and .NET Core improperly process XML documents | 高危 | NuGetSystem.Security.Cryptography.Xml | 已审查 | 2018-10-17 01:34 | 2022-04-28 03:25 |
| GHSA-HVPR-9CR6-Q5V7 CVE-2017-3159 | Apache Camel's camel-snakeyaml component is vulnerable to Java object de-serialization | 严重 | Mavenorg.apache.camel:camel-snakeyaml | 已审查 | 2018-10-17 01:21 | 2022-11-18 02:54 |
| GHSA-QXXX-2PP7-5HMX CVE-2017-7525 | jackson-databind is vulnerable to a deserialization flaw | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2018-10-17 01:21 | 2024-03-02 05:41 |