检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-H362-M8F2-5X7C CVE-2020-5229 | Password Hashing: Do not use MD5 | 低危 | Mavenorg.opencastproject:opencast-common-jpa-impl | 已审查 | 2020-01-31 05:21 | 2021-01-09 04:31 |
| GHSA-W29M-FJP4-QHMQ CVE-2020-5230 | Unsafe Identifiers in Opencast |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Mavenorg.opencastproject:base |
| 已审查 |
| 2020-01-31 05:21 |
| 2021-01-15 01:45 |
| GHSA-MH8G-HPRG-8363 CVE-2020-5222 | Hard-Coded Key Used For Remember-me Token in Opencast | 中危 | Mavenorg.opencastproject:opencast-kernel | 已审查 | 2020-01-31 05:21 | 2021-10-21 02:03 |
| GHSA-94QW-R73X-J7HG CVE-2020-5231 | Users with ROLE_COURSE_ADMIN can create new users in Opencast | 中危 | Mavenorg.opencastproject:opencast-kernel | 已审查 | 2020-01-31 05:21 | 2021-10-21 02:03 |
| GHSA-VMM6-W4CF-7F3X CVE-2020-5206 | Authentication Bypass For Endpoints With Anonymous Access in Opencast | 严重 | Mavenorg.opencastproject:opencast-kernel | 已审查 | 2020-01-31 05:21 | 2021-10-21 02:03 |
| GHSA-8W65-XJC5-9W79 CVE-2019-15607 | Cross-Site Scripting in node-red | 中危 | npmnode-red | 已审查 | 2020-01-31 05:00 | 2023-09-12 02:10 |
| GHSA-G8Q7-XV52-HF9F CVE-2020-5227 | Feedgen Vulnerable to XML Denial of Service Attacks | 中危 | PyPIfeedgen | 已审查 | 2020-01-29 06:37 | 2024-09-21 01:44 |
| GHSA-2289-PQFQ-6WX7 CVE-2019-12409 | Unrestricted upload of file with dangerous type in Apache Solr | 严重 | Mavenorg.apache.solr:solr-core | 已审查 | 2020-01-29 06:26 | 2021-08-20 00:48 |
| GHSA-V384-JQMQ-FC74 CVE-2020-7996 | XSS in Dolibarr ERP & CRM | 中危 | Packagistdolibarr/dolibarr | 已审查 | 2020-01-29 06:26 | 2021-08-20 00:47 |
| GHSA-977J-XJ7Q-2JR9 CVE-2020-5215 | Segmentation faultin TensorFlow when converting a Python string to `tf.float16` | 低危 | PyPItensorflow+2 | 已审查 | 2020-01-29 05:32 | 2024-10-31 05:27 |
| GHSA-XRR9-RH8P-433V CVE-2020-5207 | Request smuggling is possible when both chunked TE and content length specified | 低危 | Mavenio.ktor:ktor-client-cio+1 | 已审查 | 2020-01-28 03:28 | 2021-01-09 04:32 |
| GHSA-R2WF-Q3X4-HRV9 CVE-2019-10770 | Default development error handler in Ratpack is vulnerable to HTML content injection (XSS) | 中危 | Mavenio.ratpack:ratpack-core | 已审查 | 2020-01-28 03:28 | 2021-08-20 00:44 |
| GHSA-GP2M-7CFP-H6GF CVE-2017-12873 | Incorrect persistent NameID generation in SimpleSAMLphp | 严重 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-01-25 05:28 | 2024-02-08 02:42 |
| GHSA-P9CM-R7JG-8Q3G CVE-2016-9955 | Incorrect signature verification in SimpleSAMLphp | 中危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-01-25 05:27 | 2021-08-20 00:43 |
| GHSA-2R3V-Q9X3-7G46 | Link injection in SimpleSAMLphp | 低危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-01-25 05:27 | 2021-08-20 00:31 |
| GHSA-MJ9P-V2R8-WF8W CVE-2020-5226 | Cross-site scripting in SimpleSAMLphp | 低危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-01-25 05:26 | 2021-01-09 04:32 |
| GHSA-6GC6-M364-85WW CVE-2020-5225 | Log injection in SimpleSAMLphp | 低危 | Packagistsimplesamlphp/simplesamlphp | 已审查 | 2020-01-25 05:26 | 2021-01-09 04:33 |
| GHSA-5FQ8-3Q2F-4M5G CVE-2020-5224 | Session key exposure through session list in Django User Sessions | 中危 | PyPIdjango-user-sessions | 已审查 | 2020-01-25 03:56 | 2024-09-17 05:59 |
| GHSA-HXHM-96PP-2M43 CVE-2020-5219 | Remote Code Execution in Angular Expressions | 高危 | npmangular-expressions | 已审查 | 2020-01-24 23:27 | 2021-01-09 04:33 |
| GHSA-XQ52-RV6W-397C CVE-2020-5217 | Directive injection when using dynamic overrides with user input | 中危 | RubyGemssecure_headers | 已审查 | 2020-01-23 10:28 | 2023-05-17 00:09 |
| GHSA-W978-RMPF-QMWG CVE-2020-5216 | Limited header injection when using dynamic overrides with user input in RubyGems secure_headers | 中危 | RubyGemssecure_headers | 已审查 | 2020-01-23 10:27 | 2023-05-17 00:11 |
| GHSA-6X3V-RW2Q-9GX7 CVE-2019-10158 | Improper implementation of the session fixation protection in Infinispan | 严重 | Mavenorg.infinispan:infinispan-core | 已审查 | 2020-01-22 05:18 | 2023-03-29 01:25 |
| GHSA-7PM4-G2QJ-J85X CVE-2020-5397 | CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux | 中危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2020-01-22 04:59 | 2024-03-15 23:54 |
| GHSA-8WX2-9Q48-VM9R CVE-2020-5398 | RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application | 高危 | Mavenorg.springframework:spring-webflux+1 | 已审查 | 2020-01-22 04:59 | 2024-03-15 05:01 |
| GHSA-5QCG-W2CC-XFFW CVE-2019-19588 | Uncontrolled resource consumption in validators Python package | 高危 | PyPIvalidators | 已审查 | 2020-01-22 04:32 | 2024-11-19 06:16 |