检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-872G-2H8H-362Q CVE-2016-4800 | Jetty contains an alias issue that could allow unauthenticated remote code execution due to specially crafted request | 严重 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2018-10-20 00:16 | 2022-09-14 09:07 |
| GHSA-9RGV-H7X4-QW8G CVE-2018-12536 |
当前筛选结果 366,391 条 · 时间按北京时间显示
Eclipse Jetty Server generates error message containing sensitive information |
| 中危 |
Mavenorg.eclipse.jetty:jetty-server |
| 已审查 |
| 2018-10-20 00:15 |
| 2023-08-19 00:47 |
| GHSA-WFCC-PFF6-RGC5 CVE-2017-9735 | Jetty vulnerable to exposure of sensitive information due to observable discrepancy | 高危 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2018-10-20 00:15 | 2023-08-16 04:33 |
| GHSA-VGG8-72F2-QM23 CVE-2017-7657 | Critical severity vulnerability that affects org.eclipse.jetty:jetty-server | 严重 | Mavenorg.eclipse.jetty:jetty-server | 已审查 | 2018-10-20 00:15 | 2021-06-11 04:19 |
| GHSA-CR6J-3JP9-RW65 CVE-2018-11776 | Apache Struts vulnerable to remote command execution (RCE) due to improper input validation | 高危 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-19 03:24 | 2025-10-23 01:29 |
| GHSA-J77Q-2QQG-6989 CVE-2017-5638 | Apache Struts vulnerable to remote arbitrary command execution due to improper input validation | 严重 | Mavenorg.apache.struts:struts2-core | 已审查 | 2018-10-19 03:24 | 2025-10-23 01:33 |
| GHSA-7Q9C-H23X-65FQ CVE-2016-4977 | Spring Security OAuth vulnerable to remote code execution (RCE) via specially crafted request using whitelabel views | 高危 | Mavenorg.springframework.security.oauth:spring-security-oauth2 | 已审查 | 2018-10-19 02:06 | 2024-05-15 01:39 |
| GHSA-W4G2-9HJ6-5472 CVE-2018-11087 | Moderate severity vulnerability that affects com.rabbitmq:amqp-client and org.springframework.amqp:spring-amqp | 中危 | Mavencom.rabbitmq:amqp-client+1 | 已审查 | 2018-10-19 02:06 | 2021-09-21 06:35 |
| GHSA-XX65-CC7G-9PFP CVE-2018-1196 | Moderate severity vulnerability that affects org.springframework.boot:spring-boot | 中危 | Mavenorg.springframework.boot:spring-boot | 已审查 | 2018-10-19 02:05 | 2021-09-23 02:26 |
| GHSA-M9JM-RHRM-GCXJ CVE-2018-1261 | Path traversal in org.springframework.integration:spring-integration-zip | 中危 | Mavenorg.springframework.integration:spring-integration-zip | 已审查 | 2018-10-19 02:05 | 2024-04-13 05:30 |
| GHSA-RRPM-PJ7P-7J9Q CVE-2018-1260 | Spring Security OAuth vulnerable to remote code execution (RCE) | 严重 | Mavenorg.springframework.security.oauth:spring-security-oauth2 | 已审查 | 2018-10-19 02:05 | 2024-05-15 01:55 |
| GHSA-R86J-2GC6-2CQ9 CVE-2018-8025 | Race condition in org.apache.hbase:hbase-thrift | 高危 | Mavenorg.apache.hbase:hbase-thrift | 已审查 | 2018-10-19 02:05 | 2024-03-05 07:31 |
| GHSA-P8XR-4V2C-RVGP CVE-2015-1836 | High severity vulnerability that affects org.apache.hbase:hbase | 高危 | Mavenorg.apache.hbase:hbase | 已审查 | 2018-10-19 02:04 | 2021-06-11 06:05 |
| GHSA-9GP4-QRFF-C648 CVE-2016-1000345 | Moderate severity vulnerability that affects org.bouncycastle:bcprov-jdk14 and org.bouncycastle:bcprov-jdk15 | 中危 | Mavenorg.bouncycastle:bcprov-jdk14+2 | 已审查 | 2018-10-19 02:04 | 2025-09-13 03:16 |
| GHSA-2J2X-HX4G-2GF4 CVE-2016-1000344 | In Bouncy Castle JCE Provider the DHIES implementation allowed the use of ECB mode | 高危 | Mavenorg.bouncycastle:bcprov-jdk14+2 | 已审查 | 2018-10-19 01:43 | 2025-09-13 03:15 |
| GHSA-7C2R-3JQF-C9RW CVE-2016-7051 | jackson-dataformat-xml vulnerable to server side request forgery (SSRF) | 高危 | Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-xml | 已审查 | 2018-10-19 01:43 | 2022-09-14 08:19 |
| GHSA-HMQ6-FRV3-4727 CVE-2016-3720 | jackson-dataformat-xml vulnerable to XML external entity (XXE) | 严重 | Mavencom.fasterxml.jackson.dataformat:jackson-dataformat-xml | 已审查 | 2018-10-19 01:43 | 2022-09-14 08:10 |
| GHSA-RFX6-VP9G-RH7V CVE-2017-17485 | jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2018-10-19 01:42 | 2024-03-02 05:35 |
| GHSA-H592-38CM-4GGP CVE-2017-15095 | jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution | 严重 | Mavencom.fasterxml.jackson.core:jackson-databind | 已审查 | 2018-10-19 01:42 | 2024-03-15 09:13 |
| GHSA-G4GG-9F62-JFPH CVE-2015-2918 | OrientDB Studio web management interface is vulnerable to clickjacking attacks | 中危 | Mavencom.orientechnologies:orientdb-studio | 已审查 | 2018-10-19 01:41 | 2023-09-29 19:39 |
| GHSA-V6WR-FCH2-VM5W CVE-2015-2913 | OrientDB Server Community Edition uses insufficiently random values to generate session IDs | 中危 | Mavencom.orientechnologies:orientdb-server | 已审查 | 2018-10-19 01:41 | 2023-09-12 22:43 |
| GHSA-P8WW-VV84-C2RM CVE-2015-2912 | OrientDB-Server vulnerable to Cross-Site Request Forgery | 高危 | Mavencom.orientechnologies:orientdb-studio | 已审查 | 2018-10-19 01:41 | 2022-09-14 07:50 |
| GHSA-XM6R-4466-MR74 CVE-2017-11467 | OrientDB vulnerable to Improper Privilage Management leading to arbitrary command injection | 严重 | Mavencom.orientechnologies:orientdb-core | 已审查 | 2018-10-19 01:40 | 2024-02-21 00:27 |
| GHSA-XV6V-72HH-G6G2 CVE-2018-1000643 | Moderate severity vulnerability that affects org.owasp.antisamy:antisamy 已撤回 | 中危 | Mavenorg.owasp.antisamy:antisamy | 已审查 | 2018-10-19 01:22 | 2020-06-17 06:04 |
| GHSA-Q44V-XC3G-V7JQ CVE-2017-14735 | OWASP AntiSamy Cross-site Scripting vulnerability | 中危 | Mavenorg.owasp.antisamy:antisamy | 已审查 | 2018-10-19 01:22 | 2022-11-18 03:41 |