检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-5F9H-9PJV-V6J7 CVE-2020-8161 | Directory traversal in Rack::Directory app bundled with Rack | 高危 | RubyGemsrack | 已审查 | 2020-07-07 05:31 | 2022-05-27 04:45 |
| GHSA-3PC2-FM7P-Q2VG CVE-2020-4061 | Cross-site Scripting in October |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 低危 |
Packagistoctober/backend |
| 已审查 |
| 2020-07-03 00:55 |
| 2021-03-05 02:26 |
| GHSA-9QCF-C26R-X5RF CVE-2019-13990 | XML external entity injection in Terracotta Quartz Scheduler | 严重 | Mavenorg.quartz-scheduler:quartz | 已审查 | 2020-07-02 01:55 | 2024-10-16 07:33 |
| GHSA-5X3V-2GXR-59M2 CVE-2019-17572 | Directory traversal in Apache RocketMQ | 中危 | Mavenorg.apache.rocketmq:rocketmq-broker | 已审查 | 2020-07-02 01:26 | 2021-04-08 03:55 |
| GHSA-JCQ3-CPRP-M333 CVE-2019-2692 | Privilege escalation in mysql-connector-jav | 中危 | Mavenmysql:mysql-connector-java | 已审查 | 2020-07-02 01:12 | 2021-09-23 02:47 |
| GHSA-7HWC-46RM-65JH CVE-2017-7957 | Denial of service in XStream | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2020-07-01 06:48 | 2025-05-24 03:00 |
| GHSA-RGH3-987H-WPMW CVE-2016-3674 | XML External Entity Injection in XStream | 高危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2020-07-01 06:48 | 2025-05-24 03:00 |
| GHSA-9959-6P3M-WXPC CVE-2014-3488 | Denial of service in Netty | 中危 | Mavenio.netty:netty-handler | 已审查 | 2020-07-01 05:01 | 2021-09-23 02:44 |
| GHSA-XFV3-RRFM-F2RV CVE-2015-2156 | Information Exposure in Netty | 高危 | Mavenio.netty:netty+2 | 已审查 | 2020-07-01 05:01 | 2021-09-23 02:45 |
| GHSA-W3F4-3Q6J-RH82 CVE-2018-5968 | Deserialization of Untrusted Data in jackson-databind | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2020-07-01 04:40 | 2024-03-02 05:56 |
| GHSA-F6PC-CRHH-CP96 CVE-2020-15087 | Privilege escalation in Presto | 高危 | Mavenio.prestosql:presto-server | 已审查 | 2020-07-01 00:33 | 2022-10-22 08:58 |
| GHSA-6G6M-M6H5-W9GF CVE-2020-15084 | Authorization bypass in express-jwt | 高危 | npmexpress-jwt | 已审查 | 2020-07-01 00:05 | 2021-01-08 07:49 |
| GHSA-G753-JX37-7XWH | ECDSA signature vulnerability of Minerva timing attack in jsrsasign | 中危 | npmjsrsasign | 已审查 | 2020-07-01 00:05 | 2021-09-23 02:43 |
| GHSA-P8C3-7RJ8-Q963 CVE-2020-14966 | ECDSA signature validation vulnerability by accepting wrong ASN.1 encoding in jsrsasign | 高危 | npmjsrsasign | 已审查 | 2020-06-27 00:54 | 2023-01-31 09:29 |
| GHSA-J3RH-8VWQ-WH84 CVE-2019-16303 | JHipster Kotlin using insecure source of randomness `RandomStringUtils` before v1.2.0 | 严重 | npmgenerator-jhipster-kotlin | 已审查 | 2020-06-27 00:48 | 2023-01-21 02:53 |
| GHSA-XXXQ-CHMP-67G4 CVE-2020-14967 | RSA PKCS#1 decryption vulnerability with prepending zeros in jsrsasign | 严重 | npmjsrsasign | 已审查 | 2020-06-27 00:27 | 2023-01-31 09:29 |
| GHSA-Q3GH-5R98-J4H3 CVE-2020-14968 | RSA-PSS signature validation vulnerability by prepending zeros in jsrsasign | 严重 | npmjsrsasign | 已审查 | 2020-06-27 00:26 | 2023-01-28 05:41 |
| GHSA-PFXF-WH96-FVJC CVE-2020-4072 | Log Forging in generator-jhipster-kotlin | 中危 | npmgenerator-jhipster-kotlin | 已审查 | 2020-06-26 04:02 | 2021-01-08 07:50 |
| GHSA-C6QR-H5VQ-59JC CVE-2020-8185 | Untrusted users can run pending migrations in production in Rails | 中危 | RubyGemsactionpack | 已审查 | 2020-06-25 01:40 | 2023-07-06 04:24 |
| GHSA-6R3C-8XF3-GGRR | Directory traversal outside of SENDFILE_ROOT in django-sendfile2 | 中危 | PyPIdjango-sendfile2 | 已审查 | 2020-06-25 01:15 | 2021-09-23 02:37 |
| GHSA-J6W9-FV6Q-3Q52 CVE-2020-8184 | Rack allows Percent-encoded cookies to overwrite existing prefixed cookie names | 高危 | RubyGemsrack | 已审查 | 2020-06-25 01:15 | 2023-08-28 20:13 |
| GHSA-M38J-PMG3-V5X5 CVE-2020-4071 | Timing attack on django-basic-auth-ip-whitelist | 中危 | PyPIdjango-basic-auth-ip-whitelist | 已审查 | 2020-06-24 03:58 | 2024-11-19 00:26 |
| GHSA-77QV-GH6F-PGH4 CVE-2020-4066 | Command Injection in Limdu | 低危 | npmlimdu | 已审查 | 2020-06-22 23:24 | 2023-04-01 02:27 |
| GHSA-V4RH-8P82-6H5W CVE-2020-7661 | Regular expression denial of service in url-regex | 高危 | npmurl-regex | 已审查 | 2020-06-22 22:39 | 2021-09-23 02:35 |
| GHSA-QJG4-W4C6-F6C6 CVE-2020-4059 | Command injection in mversion | 高危 | npmmversion | 已审查 | 2020-06-19 03:23 | 2021-01-09 05:00 |