检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RCJJ-H6GH-JF3R CVE-2020-17521 | Information Disclosure in Apache Groovy | 中危 | Mavenorg.codehaus.groovy:groovy+1 | 已审查 | 2020-12-10 03:03 | 2024-10-18 00:18 |
| GHSA-HXMP-PQCH-C8MM CVE-2020-26257 | Denial of service attack via incorrect parameters in Matrix Synapse |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
PyPImatrix-synapse |
| 已审查 |
| 2020-12-10 02:21 |
| 2024-09-25 01:44 |
| GHSA-CG54-GPGR-4RM6 CVE-2020-26261 | user-readable api tokens in systemd units for JupyterHub | 高危 | PyPIjupyterhub-systemdspawner | 已审查 | 2020-12-10 00:27 | 2024-09-27 23:38 |
| GHSA-HM45-MGQM-GJM4 CVE-2020-26249 | Remote Code Execution (RCE) Exploit on Cross Site Scripting (XSS) Vulnerability | 中危 | PyPIred-dashboard | 已审查 | 2020-12-09 07:55 | 2024-10-26 05:50 |
| GHSA-44CW-P2HM-GPF6 CVE-2020-26234 | Disabled Hostname Verification in Opencast | 高危 | Mavenorg.opencastproject:opencast-kernel | 已审查 | 2020-12-09 06:37 | 2021-10-21 02:02 |
| GHSA-8CV5-P934-3HWP CVE-2020-26256 | Denial of service in fast-csv | 低危 | npm@fast-csv/parse+1 | 已审查 | 2020-12-09 05:42 | 2021-10-09 04:36 |
| GHSA-G3H8-CG9X-47QW CVE-2020-26255 | Kirby Panel users could upload PHP Phar archives as content files before v2.5.14 and v3.4.5 | 中危 | Packagistgetkirby/cms+1 | 已审查 | 2020-12-08 22:42 | 2022-07-21 00:59 |
| GHSA-49R3-2549-3633 CVE-2020-26254 | omniauth-apple allows attacker to fake their email address during authentication | 高危 | RubyGemsomniauth-apple | 已审查 | 2020-12-08 22:18 | 2023-05-17 00:06 |
| GHSA-5P28-63MC-CGR9 | Cross-Site Scripting bypass in html-purify | 高危 | npmhtml-purify | 已审查 | 2020-12-05 04:04 | 2020-12-05 04:02 |
| GHSA-7WWV-VH3V-89CQ | ReDOS vulnerabities: multiple grammars | 中危 | npm@highlightjs/cdn-assets+1 | 已审查 | 2020-12-05 00:47 | 2022-05-03 16:27 |
| GHSA-4FJV-PMHG-3RFG CVE-2020-26244 | Multiple cryptographic issues in Python oic | 高危 | PyPIoic | 已审查 | 2020-12-05 00:47 | 2024-10-08 05:07 |
| GHSA-M7MF-48HP-5QMR CVE-2020-16009 | Inappropriate implementation in V8 | 高危 | NuGetCefSharp.Common+3 | 已审查 | 2020-12-03 02:28 | 2023-06-07 02:43 |
| GHSA-F5GC-P5M3-V347 CVE-2020-29128 | XXE in petl | 高危 | PyPIpetl | 已审查 | 2020-12-03 02:28 | 2024-10-10 04:55 |
| GHSA-86WM-RRJM-8WH8 CVE-2020-27218 | Buffer not correctly recycled in Gzip Request inflation | 中危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2020-12-03 02:28 | 2024-02-22 01:23 |
| GHSA-47QG-Q58V-7VRP | UNEDITABLE_SCHEMAS and UNEDITABLE_TABLE_DESCRIPTION_MATCH_RULES not respected by frontend service backend | 低危 | PyPIamundsen-frontend | 已审查 | 2020-12-03 02:28 | 2020-12-02 10:18 |
| GHSA-384W-5V3F-Q499 CVE-2020-26250 | Base class whitelist configuration ignored in OAuthenticator | 高危 | PyPIoauthenticator | 已审查 | 2020-12-02 04:25 | 2024-10-02 05:19 |
| GHSA-GVQV-779R-4JGP CVE-2020-16017 | Use after free in CefSharp | 高危 | NuGetCefSharp.Common+3 | 已审查 | 2020-11-28 04:13 | 2020-11-28 04:06 |
| GHSA-X7FX-MCC9-27J7 CVE-2020-16013 | Inappropriate implementation in V8 in CefSharp | 高危 | NuGetCefSharp.Common+3 | 已审查 | 2020-11-28 04:12 | 2020-11-28 04:12 |
| GHSA-4V2W-H9JM-MQJG CVE-2020-26245 | Prototype Pollution in systeminformation | 中危 | npmsysteminformation | 已审查 | 2020-11-28 00:07 | 2021-01-08 06:40 |
| GHSA-85RR-4RH9-HHWH CVE-2020-26243 | Memory leak in Nanopb | 中危 | PyPInanopb | 已审查 | 2020-11-26 00:53 | 2021-01-08 06:39 |
| GHSA-PFJ3-56HM-JWQ5 CVE-2020-26238 | Template injection in cron-utils | 严重 | Mavencom.cronutils:cron-utils | 已审查 | 2020-11-25 07:48 | 2021-01-08 06:39 |
| GHSA-74HV-QJJQ-H7G5 | datasette-graphql leaks details of the schema of private database files | 低危 | PyPIdatasette-graphql | 已审查 | 2020-11-25 06:59 | 2020-11-25 05:42 |
| GHSA-4MP3-385R-V63F CVE-2020-26890 | Denial of service attack due to invalid JSON | 高危 | PyPImatrix-synapse | 已审查 | 2020-11-25 06:58 | 2024-10-01 04:31 |
| GHSA-VFRC-7R7C-W9MX CVE-2020-26237 | Prototype Pollution in highlight.js | 中危 | npmhighlight.js | 已审查 | 2020-11-25 06:58 | 2022-10-20 21:52 |
| GHSA-MJCR-RQJG-RHG3 | Implementation trusts the "me" field returned by the authorization server without verifying it | 严重 | PyPIdatasette-indieauth | 已审查 | 2020-11-25 05:21 | 2022-03-22 04:04 |