检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-WM47-8V5P-WJPJ CVE-2021-21295 | Possible request smuggling in HTTP/2 due missing validation | 中危 | Mavenio.netty:netty+2 | 已审查 | 2021-03-10 02:49 | 2021-09-01 05:19 |
| GHSA-CVW2-XJ8R-MJF7 CVE-2019-25025 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
RubyGemsactiverecord-session_store |
| 已审查 |
| 2021-03-09 08:45 |
| 2023-09-06 06:00 |
| GHSA-JPCM-4485-69P7 CVE-2021-21361 | Sensitive information disclosure via log in com.bmuschko:gradle-vagrant-plugin | 高危 | Mavencom.bmuschko:gradle-vagrant-plugin | 已审查 | 2021-03-09 08:38 | 2021-03-13 01:32 |
| GHSA-JFF3-MWP3-F8CW CVE-2021-21360 | Exposure of Sensitive Information to an Unauthorized Actor in Products.GenericSetup | 中危 | PyPIProducts.GenericSetup | 已审查 | 2021-03-09 08:38 | 2024-10-22 04:02 |
| GHSA-P44J-XRQG-4XRR CVE-2021-21337 | URL Redirection to Untrusted Site ('Open Redirect') in Products.PluggableAuthService | 中危 | PyPIProducts.PluggableAuthService | 已审查 | 2021-03-09 05:06 | 2024-10-22 03:59 |
| GHSA-P75F-G7GX-2R7P CVE-2021-21336 | Exposure of Sensitive Information to an Unauthorized Actor in Products.PluggableAuthService ZODBRoleManager | 高危 | PyPIProducts.PluggableAuthService | 已审查 | 2021-03-09 04:38 | 2024-10-22 04:15 |
| GHSA-R9P9-MRJM-926W CVE-2020-28498 | Elliptic Uses a Broken or Risky Cryptographic Algorithm | 中危 | npmelliptic | 已审查 | 2021-03-09 00:06 | 2023-09-07 07:43 |
| GHSA-CQFF-FX2X-P86V | botframework-connector vulnerable to Improper Authentication | 高危 | PyPIbotframework-connector | 已审查 | 2021-03-08 23:50 | 2024-09-13 23:07 |
| GHSA-QXX8-292G-2W66 | Improper Authentication | 高危 | NuGetMicrosoft.Bot.Connector | 已审查 | 2021-03-08 23:50 | 2021-03-08 23:48 |
| GHSA-FVCJ-HVFW-7F2V CVE-2021-1725 | botframework-connector vulnerable to Improper Authentication | 中危 | npmbotframework-connector | 已审查 | 2021-03-08 23:49 | 2024-01-02 23:05 |
| GHSA-2CXF-6567-7PP6 CVE-2021-21331 | Local Information Disclosure Vulnerability | 低危 | Mavencom.datadoghq:datadog-api-client | 已审查 | 2021-03-04 07:01 | 2021-07-09 01:02 |
| GHSA-52MQ-6JCV-J79X CVE-2021-21320 | User content sandbox can be confused into opening arbitrary documents | 低危 | npmmatrix-react-sdk | 已审查 | 2021-03-03 10:23 | 2021-04-15 03:07 |
| GHSA-C4QR-GMR9-V23W CVE-2021-21322 | Prefix escape | 低危 | npmfastify-http-proxy | 已审查 | 2021-03-03 10:18 | 2021-03-02 11:32 |
| GHSA-P493-635Q-R6GR CVE-2021-21353 | Remote code execution via the `pretty` option. | 中危 | npmpug+1 | 已审查 | 2021-03-03 10:03 | 2025-04-17 06:09 |
| GHSA-QMW8-3V4G-GWJ4 CVE-2021-21321 | Prefix escape | 严重 | npmfastify-reply-from | 已审查 | 2021-03-03 09:52 | 2021-03-02 11:32 |
| GHSA-8877-PRQ4-9XFW CVE-2021-22881 | Actionpack Open Redirect Vulnerability | 中危 | RubyGemsactionpack | 已审查 | 2021-03-02 11:44 | 2023-07-04 06:06 |
| GHSA-8HC4-XXM3-5PPP CVE-2021-22880 | Active Record subject to Regular Expression Denial-of-Service (ReDoS) | 高危 | RubyGemsactiverecord | 已审查 | 2021-03-02 11:44 | 2023-07-04 06:08 |
| GHSA-W5HR-JM4J-9JVQ CVE-2021-26119 | Sandbox escape through template_object in smarty | 高危 | Packagistsmarty/smarty | 已审查 | 2021-03-02 10:57 | 2022-05-03 11:42 |
| GHSA-9FHW-R42P-5C7R CVE-2021-27405 | Regular expression Denial of Service in @progfay/scrapbox-parser | 中危 | npm@progfay/scrapbox-parser | 已审查 | 2021-03-02 04:44 | 2021-02-27 03:49 |
| GHSA-P6J9-7XHC-RHWP CVE-2021-27516 | URIjs Hostname spoofing via backslashes in URL | 高危 | npmurijs | 已审查 | 2021-03-02 04:03 | 2023-09-08 04:24 |
| GHSA-FQ6P-X6J3-CMMQ CVE-2020-28496 | Denial of service in three | 高危 | npmthree | 已审查 | 2021-03-02 03:57 | 2023-09-12 00:30 |
| GHSA-H4HR-7FG3-H35W CVE-2021-23341 | Denial of service in prismjs | 高危 | npmprismjs | 已审查 | 2021-03-02 03:52 | 2023-09-06 06:59 |
| GHSA-2MM9-C2FX-C7M4 CVE-2021-23342 | Docsify XSS Vulnerability | 中危 | npmdocsify | 已审查 | 2021-03-02 03:44 | 2023-09-14 04:21 |
| GHSA-XR9H-9M79-X29G CVE-2020-8902 | SSRF in Rendertron | 中危 | npmrendertron | 已审查 | 2021-03-02 03:38 | 2021-02-24 14:59 |
| GHSA-2HWX-MJRM-V3G8 CVE-2021-21274 | Denial of service attack via .well-known lookups | 中危 | PyPImatrix-synapse | 已审查 | 2021-03-02 03:34 | 2024-10-01 04:23 |