检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-9W6V-M7WP-JWG4 CVE-2020-11021 | Http request which redirect to another hostname do not strip authorization header in @actions/http-client | 中危 | npm@actions/http-client | 已审查 | 2020-04-30 01:58 | 2021-08-26 05:03 |
| GHSA-QPG4-4W7W-2MQ5 CVE-2020-11020 | Authentication and extension bypass in Faye |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 高危 |
RubyGemsfaye |
| 已审查 |
| 2020-04-30 01:41 |
| 2023-05-16 23:51 |
| GHSA-6M9G-JR8C-CQW3 CVE-2019-1000007 | Depth counting error in guard() leading to multiple potential security issues in aioxmpp | 高危 | PyPIaioxmpp | 已审查 | 2020-04-30 01:12 | 2024-09-05 03:55 |
| GHSA-5679-7QRC-5M7J CVE-2020-11009 | IDOR can reveal execution data and logs to unauthorized user in Rundeck | 中危 | Mavenorg.rundeck:rundeck | 已审查 | 2020-04-30 00:31 | 2021-09-03 02:48 |
| GHSA-QH4W-7PW3-P4RP CVE-2015-4411 | BSON rubygem contains potential denial of service | 高危 | RubyGemsbson | 已审查 | 2020-04-29 23:34 | 2023-08-26 05:29 |
| GHSA-758M-V56V-GRJ4 CVE-2020-10969 | jackson-databind mishandles the interaction between serialization gadgets and typing | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2020-04-24 05:36 | 2024-06-25 21:46 |
| GHSA-5P34-5M6P-P58G CVE-2020-9546 | jackson-databind mishandles the interaction between serialization gadgets and typing | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2020-04-24 05:08 | 2026-05-07 02:37 |
| GHSA-H4RC-386G-6M85 CVE-2020-11620 | jackson-databind mishandles the interaction between serialization gadgets and typing | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2020-04-24 04:19 | 2024-03-15 08:41 |
| GHSA-426H-24VJ-QWXF CVE-2020-7614 | Command Injection in npm-programmatic | 严重 | npmnpm-programmatic | 已审查 | 2020-04-24 04:09 | 2021-07-29 23:52 |
| GHSA-95CM-88F5-F2C7 CVE-2020-10672 | jackson-databind mishandles the interaction between serialization gadgets and typing | 高危 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2020-04-24 00:32 | 2024-07-04 05:10 |
| GHSA-FV3H-8X5J-PVGQ CVE-2020-11888 | XSS in python-markdown2 | 中危 | PyPImarkdown2 | 已审查 | 2020-04-23 04:59 | 2024-09-25 04:27 |
| GHSA-24M3-W8G9-JWPQ CVE-2020-5301 | Information disclosure of source code in SimpleSAMLphp | 低危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-04-23 04:59 | 2024-02-06 21:27 |
| GHSA-9475-XG6M-J7PW CVE-2020-5268 | Subject Confirmation Method not validated in Saml2 Authentication Services for ASP.NET | 中危 | NuGetSustainsys.Saml2 | 已审查 | 2020-04-23 04:59 | 2021-01-09 04:21 |
| GHSA-W8RC-PGXQ-X2CJ CVE-2020-11007 | Negative charge in shopping cart in Shopizer | 严重 | Mavencom.shopizer:sm-core-model | 已审查 | 2020-04-23 04:59 | 2021-01-09 05:09 |
| GHSA-9J2C-X8QM-QMJQ CVE-2020-11010 | SQL injection in Tortoise ORM | 中危 | PyPItortoise-orm | 已审查 | 2020-04-21 05:31 | 2024-11-14 06:53 |
| GHSA-Q8XG-8XWF-M598 CVE-2020-10800 | Machine-In-The-Middle in lix | 高危 | npmlix | 已审查 | 2020-04-16 11:14 | 2021-09-17 04:39 |
| GHSA-PC5P-H8PF-MVWP | Machine-In-The-Middle in https-proxy-agent | 中危 | npmhttps-proxy-agent | 已审查 | 2020-04-16 11:14 | 2023-11-02 04:54 |
| GHSA-265Q-28RP-CHQ5 CVE-2015-8851 | Insecure Entropy Source - Math.random() in node-uuid | 高危 | npmnode-uuid | 已审查 | 2020-04-16 11:14 | 2021-08-23 23:25 |
| GHSA-3J7M-HMH3-9JMP CVE-2016-1000237 | Cross-Site Scripting in sanitize-html | 中危 | npmsanitize-html | 已审查 | 2020-04-16 11:14 | 2021-08-23 23:18 |
| GHSA-J438-45HC-VJHM CVE-2020-11003 | CSRF and DNS Rebinding in Oasis | 中危 | npm@fraction/oasis | 已审查 | 2020-04-16 11:14 | 2021-01-09 04:59 |
| GHSA-3GG7-9Q2X-79FC CVE-2020-1728 | Improper Restriction of Rendered UI Layers or Frames in Keycloak | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2020-04-16 05:09 | 2020-04-16 05:07 |
| GHSA-6PMV-7PR9-CGRJ CVE-2020-1731 | Predictable password in Keycloak | 严重 | Mavenorg.keycloak:keycloak-core | 已审查 | 2020-04-16 05:09 | 2021-08-23 23:17 |
| GHSA-8VF3-4W62-M3PQ CVE-2020-1697 | XSS in Keycloak | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2020-04-16 05:09 | 2021-08-23 23:16 |
| GHSA-XFQH-7356-VQJJ CVE-2019-14820 | Exposure of Sensitive Information to an Unauthorized Actor in Keycloak | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2020-04-16 05:08 | 2021-11-01 22:08 |
| GHSA-RC5R-697F-28X6 CVE-2019-12186 | XSS injection in the Grid component of Sylius | 中危 | Packagistsylius/grid+2 | 已审查 | 2020-04-16 05:07 | 2024-02-26 20:35 |