检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-683W-6H9J-57WQ CVE-2016-10006 | OWASP AntiSamy vulnerable to Cross-site Scripting | 中危 | Mavenorg.owasp.antisamy:antisamy | 已审查 | 2018-10-19 01:21 | 2025-04-15 06:05 |
| GHSA-FV7X-4HPC-HF9F CVE-2017-12631 | Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3 |
当前筛选结果 366,391 条 · 时间按北京时间显示
| 中危 |
Mavenorg.apache.cxf.fediz:fediz-spring+2 |
| 已审查 |
| 2018-10-19 00:57 |
| 2024-04-13 05:04 |
| GHSA-QPWJ-MVV7-V3M9 CVE-2016-4464 | High severity vulnerability that affects org.apache.cxf.fediz:fediz-spring and org.apache.cxf.fediz:fediz-spring2 | 高危 | Mavenorg.apache.cxf.fediz:fediz-spring+1 | 已审查 | 2018-10-19 00:57 | 2020-06-17 05:52 |
| GHSA-3357-829X-M9PR CVE-2015-5175 | Apache CXF Fediz application plugins are vulnerable to Denial of Service (DoS) attacks | 高危 | Mavenorg.apache.cxf.fediz:fediz-core+1 | 已审查 | 2018-10-19 00:57 | 2022-09-14 07:37 |
| GHSA-W3GH-G32M-CVHR CVE-2018-8038 | High severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, org.apache.cxf.fediz:fediz-spring, org.apache.cxf.fediz:fediz-spring2, and org.apache.cxf.fediz:fediz-spring3 | 高危 | Mavenorg.apache.cxf.fediz:fediz-jetty8+4 | 已审查 | 2018-10-19 00:56 | 2020-06-17 05:59 |
| GHSA-WHW7-H25V-9QVX CVE-2017-7661 | Moderate severity vulnerability that affects org.apache.cxf.fediz:fediz-jetty8, org.apache.cxf.fediz:fediz-jetty9, and org.apache.cxf.fediz:fediz-spring2 | 中危 | Mavenorg.apache.cxf.fediz:fediz-jetty8+2 | 已审查 | 2018-10-19 00:56 | 2020-06-17 06:00 |
| GHSA-R32R-3977-CGC3 CVE-2014-3651 | Keycloak vulnerable to uncontrolled resource consumption | 高危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:50 | 2022-09-14 07:34 |
| GHSA-959Q-32G8-VVP7 CVE-2017-12161 | Moderate severity vulnerability that affects org.keycloak:keycloak-core | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:50 | 2020-06-17 05:27 |
| GHSA-H7J7-PW3V-3V3X CVE-2018-10912 | Moderate severity vulnerability that affects org.keycloak:keycloak-core | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:49 | 2021-09-14 23:43 |
| GHSA-C77R-6F64-478Q CVE-2017-2582 | keycloak-core discloses system properties | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:49 | 2023-09-08 04:32 |
| GHSA-JC6Q-27MW-P55W CVE-2017-2646 | Keycloak vulnerable to infinite loop based Denial of Service | 高危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:49 | 2022-09-14 07:31 |
| GHSA-95M6-MJH3-58GM CVE-2016-8609 | Improper Authentication in org.keycloak:keycloak-core | 高危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:48 | 2022-09-17 08:55 |
| GHSA-QGM9-232X-HWPX CVE-2017-1000500 | Moderate severity vulnerability that affects org.keycloak:keycloak-core 已撤回 | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:48 | 2021-01-30 01:10 |
| GHSA-778X-2MQV-W6XW CVE-2016-8629 | Moderate severity vulnerability that affects org.keycloak:keycloak-core | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:48 | 2020-06-17 05:21 |
| GHSA-W6GV-3R3V-GWGJ CVE-2017-2585 | keycloak-core vulnerable to timing attacks against JWS token verification | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2018-10-19 00:47 | 2023-09-08 04:31 |
| GHSA-387V-84CV-9QMC CVE-2017-3163 | Improper Limitation of a Pathname ('Path Traversal') in org.apache.solr:solr-core | 高危 | Mavenorg.apache.solr:solr-core | 已审查 | 2018-10-19 00:40 | 2022-09-17 08:06 |
| GHSA-8CRV-49FR-2H6J CVE-2016-5007 | Spring Security and Spring Framework may not recognize certain paths that should be protected | 高危 | Mavenorg.springframework:spring-core+1 | 已审查 | 2018-10-18 04:30 | 2024-03-06 01:55 |
| GHSA-PGF9-H69P-PCGF CVE-2015-5211 | Files or Directories Accessible to External Parties in org.springframework:spring-core | 高危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-18 04:29 | 2024-03-06 02:07 |
| GHSA-6V7W-535J-RQ5M CVE-2015-3192 | Pivotal Spring Framework DoS Attack with XML Input | 中危 | Mavenorg.springframework:spring-web | 已审查 | 2018-10-18 04:29 | 2024-03-06 02:17 |
| GHSA-45VG-2V73-VM62 CVE-2015-0201 | Moderate severity vulnerability that affects org.springframework:spring-core | 中危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-18 04:28 | 2024-03-06 02:20 |
| GHSA-3RMV-2PG5-XVQJ CVE-2018-1275 | Spring Framework has Improperly Implemented Security Check for Standard | 严重 | Mavenorg.springframework:spring-messaging | 已审查 | 2018-10-18 04:28 | 2025-02-01 03:35 |
| GHSA-4487-X383-QPPH CVE-2018-1272 | Possible privilege escalation in org.springframework:spring-core | 高危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-18 04:27 | 2024-03-09 04:42 |
| GHSA-G8HW-794C-4J9G CVE-2018-1271 | Path Traversal in org.springframework:spring-core | 中危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-18 04:07 | 2024-03-08 05:32 |
| GHSA-P5HG-3XM3-GCJG CVE-2018-1270 | Spring Framework allows applications to expose STOMP over WebSocket endpoints | 严重 | Mavenorg.springframework:spring-messaging | 已审查 | 2018-10-18 04:05 | 2025-02-01 02:51 |
| GHSA-CXRJ-66C5-9FMH CVE-2018-1258 | Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass | 高危 | Mavenorg.springframework:spring-core | 已审查 | 2018-10-18 04:05 | 2024-03-15 05:08 |