检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-G9FW-9X87-RMRJ CVE-2020-7020 | Privilege Context Switching Error in Elasticsearch | 低危 | Mavenorg.elasticsearch:elasticsearch | 已审查 | 2021-03-19 03:27 | 2022-06-07 01:56 |
| GHSA-HWVV-438R-MHVJ CVE-2021-22134 | Exposure of Sensitive Information to an Unauthorized Actor |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Mavenorg.elasticsearch:elasticsearch |
| 已审查 |
| 2021-03-19 03:23 |
| 2022-04-23 00:50 |
| GHSA-PJJ4-JJGC-H3R8 | Authenticated remote code execution | 中危 | Packagistshopware/platform | 已审查 | 2021-03-13 07:09 | 2021-03-13 06:28 |
| GHSA-H9Q8-5GV2-V6MG CVE-2021-32710 | Potential Session Hijacking | 低危 | Packagistshopware/platform | 已审查 | 2021-03-13 07:09 | 2026-02-03 05:01 |
| GHSA-HFWX-C7Q6-G54C | Vulnerability allowing for reading internal HTTP resources | 高危 | npmhighcharts-export-server | 已审查 | 2021-03-13 07:04 | 2021-03-13 06:32 |
| GHSA-753C-PHHG-CJ29 CVE-2021-23352 | Madge vulnerable to command injection | 高危 | npmmadge | 已审查 | 2021-03-13 07:01 | 2023-09-07 07:33 |
| GHSA-4WV4-MGFQ-598V | Code injection in nobelprizeparser | 严重 | npmnobelprizeparser | 已审查 | 2021-03-13 07:00 | 2021-03-13 03:13 |
| GHSA-GMJW-49P4-PCFM CVE-2021-21368 | Prototype poisoning | 中危 | npmmsgpack5 | 已审查 | 2021-03-13 06:44 | 2021-03-13 00:57 |
| GHSA-H6Q6-9HQW-RWFV CVE-2021-21366 | Misinterpretation of malicious XML input | 中危 | npmxmldom | 已审查 | 2021-03-13 06:39 | 2023-01-03 05:51 |
| GHSA-XMH9-RG6F-J3MR | Verification flaw in Solid identity-token-verifier | 中危 | npm@solid/identity-token-verifier | 已审查 | 2021-03-13 06:39 | 2021-03-10 12:01 |
| GHSA-J29G-G982-PWPV CVE-2020-17551 | Cross-site scripting (XSS) | 中危 | Packagistimpresscms/impresscms | 已审查 | 2021-03-13 05:34 | 2021-03-13 04:09 |
| GHSA-79HV-PFX6-HHPJ CVE-2021-28088 | Cross-site scripting (XSS) | 中危 | Packagistimpresscms/impresscms | 已审查 | 2021-03-13 05:34 | 2021-03-13 03:56 |
| GHSA-G2FG-MR77-6VRM CVE-2020-13949 | Uncontrolled Resource Consumption in Apache Thrift | 高危 | Mavenorg.apache.thrift:libthrift | 已审查 | 2021-03-13 05:33 | 2022-02-09 05:37 |
| GHSA-XF46-8VVP-4HXX CVE-2021-20262 | Keycloak Missing authentication for critical function | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2021-03-13 05:33 | 2023-09-08 02:44 |
| GHSA-57F3-GGHM-9MHC CVE-2021-23353 | jspdf vulnerable to Regular Expression Denial of Service (ReDoS) | 高危 | npmjspdf | 已审查 | 2021-03-13 05:28 | 2023-09-09 04:22 |
| GHSA-FH63-4R66-JC7V CVE-2020-13959 | Cross-site scripting (XSS) in Apache Velocity Tools | 中危 | Mavenorg.apache.velocity:velocity-tools+1 | 已审查 | 2021-03-13 04:24 | 2022-04-26 07:35 |
| GHSA-2V5F-23XC-V9QR CVE-2021-3377 | ansi_up cross-site scripting vulnerability | 中危 | npmansi_up | 已审查 | 2021-03-12 06:50 | 2025-11-05 00:33 |
| GHSA-5Q6M-3H65-W53X CVE-2021-24033 | react-dev-utils OS Command Injection in function `getProcessForPort` | 中危 | npmreact-dev-utils | 已审查 | 2021-03-12 06:26 | 2022-08-04 01:21 |
| GHSA-GMRF-99GW-VVWJ CVE-2021-46876 | /user/sessions endpoint allows detecting valid accounts | 中危 | Packagistezsystems/ezpublish-kernel | 已审查 | 2021-03-12 01:42 | 2026-02-04 01:38 |
| GHSA-7VWG-39H8-8QP8 | /user/sessions endpoint allows detecting valid accounts | 高危 | Packagistezsystems/ezplatform-rest | 已审查 | 2021-03-12 01:42 | 2021-03-12 01:41 |
| GHSA-HPV8-9RQ5-HQ7W CVE-2021-21364 | Generated Code Contains Local Information Disclosure Vulnerability | 中危 | Mavenio.swagger:swagger-codegen | 已审查 | 2021-03-11 11:09 | 2022-10-26 04:35 |
| GHSA-PC22-3G76-GM6J CVE-2021-21363 | Generator Web Application: Local Privilege Escalation Vulnerability via System Temp Directory | 低危 | Mavenio.swagger:swagger-codegen | 已审查 | 2021-03-11 11:09 | 2021-03-23 07:45 |
| GHSA-8278-88VV-X98R CVE-2021-21371 | Execution of untrusted code through config file | 中危 | PyPItenable-jira-cloud | 已审查 | 2021-03-11 05:51 | 2024-10-27 23:38 |
| GHSA-XHFX-HGMF-V6VP CVE-2021-21265 | October CMS vulnerable to Potential Host Header Poisoning on misconfigured servers | 低危 | Packagistoctober/backend | 已审查 | 2021-03-11 05:07 | 2025-05-30 07:26 |
| GHSA-M394-8RWW-3JR7 CVE-2020-27223 | DOS vulnerability for Quoted Quality CSV headers | 中危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2021-03-10 11:46 | 2021-10-21 22:14 |