检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-HHX9-P69V-CX2J CVE-2020-13927 | Authentication bypass in Apache Airflow | 严重 | PyPIapache-airflow | 已审查 | 2021-05-01 01:34 | 2025-10-23 01:56 |
| GHSA-77PW-C3J2-5FC8 CVE-2020-13952 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
PyPIapache-superset |
| 已审查 |
| 2021-05-01 01:34 |
| 2024-09-05 03:27 |
| GHSA-3GQJ-CMXR-P4X2 CVE-2016-1000111 | Forced Browsing in Twisted | 中危 | PyPITwisted | 已审查 | 2021-05-01 01:32 | 2024-11-19 06:24 |
| GHSA-HMV2-79Q8-FV6G CVE-2020-7212 | Uncontrolled Resource Consumption in urllib3 | 高危 | PyPIurllib3 | 已审查 | 2021-05-01 01:31 | 2024-11-19 06:23 |
| GHSA-8CR8-4VFW-MR7H CVE-2021-28965 | REXML round-trip instability | 高危 | RubyGemsrexml | 已审查 | 2021-05-01 01:30 | 2022-08-23 03:43 |
| GHSA-QGP4-5QX6-548G CVE-2021-29460 | Cross-site scripting (XSS) from unsanitized uploaded SVG files in Kirby | 高危 | Packagistgetkirby/cms | 已审查 | 2021-05-01 01:30 | 2021-04-28 04:11 |
| GHSA-RV39-3QH7-9V7W CVE-2020-5421 | Improper Input Validation in Spring Framework | 中危 | Mavenorg.springframework:spring-framework-bom | 已审查 | 2021-05-01 01:29 | 2022-02-09 06:03 |
| GHSA-QGCG-P3V2-9H4P CVE-2020-5412 | Externally Controlled Reference to a Resource in Another Sphere and Confused Deputy in Spring Cloud Netflix | 中危 | Mavenorg.springframework.cloud:spring-cloud-netflix | 已审查 | 2021-05-01 01:29 | 2021-04-28 05:33 |
| GHSA-RHH9-CM65-3W54 CVE-2018-11765 | Improper Authentication in Apache Hadoop | 高危 | Mavenorg.apache.hadoop:hadoop-main | 已审查 | 2021-05-01 01:29 | 2021-10-06 00:27 |
| GHSA-78VQ-9J56-WRFR CVE-2020-25739 | Gon gem lack of escaping certain input when outputting as JSON | 中危 | RubyGemsgon | 已审查 | 2021-05-01 01:29 | 2023-08-29 20:13 |
| GHSA-P9W3-GWC2-CR49 CVE-2020-10687 | HTTP Request Smuggling in Undertow | 中危 | Mavenio.undertow:undertow-core | 已审查 | 2021-05-01 01:28 | 2022-02-12 05:12 |
| GHSA-G4CP-H53P-V3V8 CVE-2020-10705 | Allocation of Resources Without Limits or Throttling in Undertow | 高危 | Mavenio.undertow:undertow-core | 已审查 | 2021-05-01 01:28 | 2022-02-12 05:12 |
| GHSA-CCCF-7XW3-P2VR CVE-2020-10719 | HTTP Request Smuggling in Undertow | 中危 | Mavenio.undertow:undertow-core | 已审查 | 2021-05-01 01:28 | 2022-02-12 05:12 |
| GHSA-RFW2-X9F8-2F6M CVE-2021-26722 | LinkedIn Oncall vulnerable to Cross-Site Scripting | 中危 | PyPIoncall | 已审查 | 2021-05-01 01:27 | 2024-10-08 05:22 |
| GHSA-73XV-W5GP-FRXH CVE-2020-28052 | Logic error in Legion of the Bouncy Castle BC Java | 高危 | Mavenorg.bouncycastle:bcprov-ext-jdk15on+6 | 已审查 | 2021-05-01 00:14 | 2022-02-09 06:01 |
| GHSA-9FGX-Q25H-JXRG CVE-2021-29484 | DOM XSS in Theme Preview | 中危 | npmghost | 已审查 | 2021-04-30 05:53 | 2022-11-22 03:46 |
| GHSA-Q348-F93X-9GX4 CVE-2021-30492 | Lack of Input Validation in zendesk_api_client_php for Zendesk Subdomain | 严重 | Packagistzendesk/zendesk_api_client_php | 已审查 | 2021-04-30 05:53 | 2021-04-29 06:29 |
| GHSA-4MG9-VHXQ-VM7J | SQL Server LIMIT / OFFSET SQL Injection in laravel/framework and illuminate/database | 高危 | Packagistilluminate/database+1 | 已审查 | 2021-04-30 05:52 | 2021-11-19 03:46 |
| GHSA-52QP-JPQ7-6C54 CVE-2021-29476 | Insecure Deserialization of untrusted data in rmccue/requests | 严重 | Packagistrmccue/requests | 已审查 | 2021-04-30 05:52 | 2021-04-28 04:54 |
| GHSA-H5H8-PC6H-JVVX CVE-2021-29472 | Composer's missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial | 高危 | Packagistcomposer/composer | 已审查 | 2021-04-30 05:52 | 2022-08-11 08:19 |
| GHSA-867Q-77CC-98MV CVE-2021-21429 | Creation of Temporary File in Directory with Insecure Permissions in the OpenAPI Generator Maven plugin | 中危 | Mavenorg.openapitools:openapi-generator-maven-plugin | 已审查 | 2021-04-30 05:51 | 2021-05-11 03:29 |
| GHSA-P48W-VF3C-RQJX CVE-2021-21365 | Cross-Site Scripting in Bootstrap Package | 中危 | Packagistbk2k/bootstrap-package | 已审查 | 2021-04-30 05:51 | 2021-04-28 03:43 |
| GHSA-XV5H-V7JH-P2QH CVE-2021-29442 | Authentication bypass for specific endpoint | 高危 | Mavencom.alibaba.nacos:nacos-common | 已审查 | 2021-04-28 04:09 | 2021-05-10 23:11 |
| GHSA-36HP-JR8H-556F CVE-2021-29441 | Authentication Bypass | 高危 | Mavencom.alibaba.nacos:nacos-common | 已审查 | 2021-04-28 04:09 | 2021-05-10 22:56 |
| GHSA-35Q2-47Q7-3PC3 CVE-2021-29469 | Node-Redis potential exponential regex in monitor mode | 高危 | npmredis | 已审查 | 2021-04-27 23:56 | 2022-08-11 08:21 |