检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3VG7-JW9M-PC3F CVE-2021-21357 | Broken Access Control in Form Framework | 高危 | Packagisttypo3/cms+2 | 已审查 | 2021-03-23 09:53 | 2021-03-30 02:01 |
| GHSA-2R6J-862C-M2V2 CVE-2021-21355 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
Packagisttypo3/cms+2 |
| 已审查 |
| 2021-03-23 09:53 |
| 2021-03-30 02:01 |
| GHSA-FJH3-G8GQ-9Q92 CVE-2021-21340 | Cross-Site Scripting in Content Preview | 中危 | Packagisttypo3/cms+2 | 已审查 | 2021-03-23 09:53 | 2024-02-03 00:44 |
| GHSA-QX3W-4864-94CH CVE-2021-21339 | Cleartext storage of session identifier | 中危 | Packagisttypo3/cms+1 | 已审查 | 2021-03-23 09:53 | 2021-03-30 01:59 |
| GHSA-4JHW-2P6J-5WMP CVE-2021-21338 | Open Redirection in Login Handling | 中危 | Packagisttypo3/cms+1 | 已审查 | 2021-03-23 09:53 | 2021-03-30 02:07 |
| GHSA-HRCP-8F3Q-4W2C CVE-2021-21351 | XStream is vulnerable to an Arbitrary Code Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:29 | 2022-02-09 05:32 |
| GHSA-43GC-MJXG-GVRQ CVE-2021-21350 | XStream is vulnerable to an Arbitrary Code Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:29 | 2022-02-09 05:31 |
| GHSA-F6HM-88X3-MFJV CVE-2021-21349 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:29 | 2022-02-09 05:32 |
| GHSA-56P8-3FH9-4CVQ CVE-2021-21348 | XStream is vulnerable to an attack using Regular Expression for a Denial of Service (ReDos) | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:29 | 2022-02-09 05:32 |
| GHSA-QPFQ-PH7R-QV6F CVE-2021-21347 | XStream is vulnerable to an Arbitrary Code Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:29 | 2022-02-09 05:32 |
| GHSA-4HRM-M67V-5CXR CVE-2021-21346 | XStream is vulnerable to an Arbitrary Code Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:28 | 2022-02-09 05:32 |
| GHSA-HWPC-8XQV-JVJ4 CVE-2021-21345 | XStream is vulnerable to a Remote Command Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:28 | 2022-10-26 04:37 |
| GHSA-59JW-JQF4-3WQ3 CVE-2021-21344 | XStream is vulnerable to an Arbitrary Code Execution attack | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:28 | 2022-02-09 05:33 |
| GHSA-74CV-F58X-F9WF CVE-2021-21343 | XStream is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling as long as the executing process has sufficient rights | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:28 | 2022-02-09 05:32 |
| GHSA-HVV8-336G-RX3M CVE-2021-21342 | A Server-Side Forgery Request can be activated unmarshalling with XStream to access data streams from an arbitrary URL referencing a resource in an intranet or the local host | 中危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:28 | 2023-03-10 05:21 |
| GHSA-2P3X-QW9C-25HH CVE-2021-21341 | XStream can cause a Denial of Service. | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2021-03-23 07:27 | 2022-02-09 05:33 |
| GHSA-QWWR-QC2P-6283 CVE-2018-14550 | Out-of-bounds write in libpng | 高危 | NuGetlibpng | 已审查 | 2021-03-23 00:57 | 2021-10-22 05:19 |
| GHSA-JQ4V-F5Q6-MJQQ CVE-2021-28957 | lxml vulnerable to Cross-Site Scripting | 中危 | PyPIlxml | 已审查 | 2021-03-23 00:53 | 2024-10-01 00:54 |
| GHSA-FX83-3PH3-9J2Q CVE-2020-25626 | Cross-site Scripting (XSS) in Django REST Framework | 中危 | PyPIdjangorestframework | 已审查 | 2021-03-20 05:32 | 2024-09-20 22:56 |
| GHSA-3WJ8-VP9H-RM6M CVE-2021-23344 | total.js Remote Code Execution Vulnerability | 严重 | npmtotal.js | 已审查 | 2021-03-20 05:32 | 2023-09-14 04:23 |
| GHSA-V542-8Q9X-CFFC CVE-2020-35681 | Django Channels leakage of session identifiers using legacy AsgiHandler | 高危 | PyPIchannels | 已审查 | 2021-03-20 05:29 | 2024-09-14 01:49 |
| GHSA-G3RQ-G295-4J3M CVE-2020-28493 | Regular Expression Denial of Service (ReDoS) in Jinja2 | 中危 | PyPIJinja2 | 已审查 | 2021-03-20 05:28 | 2024-09-25 04:40 |
| GHSA-7R28-3M3F-R2PR CVE-2021-28092 | Regular Expression Denial of Service (ReDoS) | 高危 | npmis-svg | 已审查 | 2021-03-20 05:25 | 2023-08-16 06:24 |
| GHSA-VX3P-948G-6VHQ CVE-2021-27290 | Regular Expression Denial of Service (ReDoS) | 高危 | npmssri | 已审查 | 2021-03-20 05:24 | 2021-10-22 01:38 |
| GHSA-XFHP-GMH8-R8V2 CVE-2021-23354 | printf vulnerable to Regular Expression Denial of Service (ReDoS) | 高危 | npmprintf | 已审查 | 2021-03-20 05:22 | 2023-09-09 04:24 |