检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-RC7V-65V6-M2V3 | Withdrawn Advisory: go-mysql affected by go.uuid's Predictable UUID Identifiers 已撤回 | 严重 | Gogithub.com/go-mysql-org/go-mysql | 已审查 | 2024-10-28 23:12 | 2024-11-09 01:25 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-J42F-WC6V-5XPQ |
Duplicate Advisory: Permissive Regular Expression in tacquito 已撤回 |
| 严重 |
Gogithub.com/tacquito/tacquito |
| 已审查 |
| 2024-10-18 02:31 |
| 2024-11-02 05:47 |
| GHSA-F8X4-F32R-W556 | Duplicate Advisory: PyO3 has a risk of use-after-free in `borrowed` reads from Python weak references 已撤回 | 中危 | crates.iopyo3 | 已审查 | 2024-10-15 22:08 | 2024-10-16 01:13 |
| GHSA-MQ92-JR35-FFPC CVE-2024-7038 | Withdrawn Advisory: open-webui allows enumeration of file names and traversal of directories by observing the error messages 已撤回 | 低危 | PyPIopen-webui | 已审查 | 2024-10-10 05:31 | 2026-09-02 22:29 |
| GHSA-MRW8-5368-PHM3 CVE-2024-45965 | Duplicate Advisory: Contao allows admin an account to upload SVG file containing malicious JavaScript 已撤回 | 低危 | Packagistcontao/contao | 已审查 | 2024-10-03 05:30 | 2025-04-22 23:17 |
| GHSA-PHH4-3HMM-24RX | Duplicate Advisory: Juju makes Use of Weak Credentials 已撤回 | 高危 | Gogithub.com/juju/juju | 已审查 | 2024-10-02 20:30 | 2025-08-27 03:43 |
| GHSA-FC27-7PF5-96V3 | Duplicate Advisory: Vulnerable juju hook tool abstract UNIX domain socket 已撤回 | 中危 | Gogithub.com/juju/juju | 已审查 | 2024-10-02 20:30 | 2024-10-03 05:55 |
| GHSA-85QF-6845-M8P2 | Duplicate Advisory: Juju Unprotected Alternate Channel vulnerability 已撤回 | 高危 | Gogithub.com/juju/juju | 已审查 | 2024-10-02 20:30 | 2024-10-03 05:55 |
| GHSA-R2JW-C95Q-RJ29 | Duplicate Advisory: cocoon Reuses a Nonce, Key Pair in Encryption 已撤回 | 中危 | crates.iococoon | 已审查 | 2024-10-02 14:30 | 2025-12-30 06:23 |
| GHSA-G4PJ-MX9F-M2MH | Duplicate Advisory: NVIDIA Container Toolkit allows specially crafted container image to create empty files on the host file system 已撤回 | 中危 | Gogithub.com/NVIDIA/nvidia-container-toolkit | 已审查 | 2024-09-26 14:30 | 2024-10-30 03:52 |
| GHSA-536J-XXHG-6PGG | Duplicate Advisory: NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability 已撤回 | 严重 | Gogithub.com/NVIDIA/nvidia-container-toolkit | 已审查 | 2024-09-26 14:30 | 2024-10-30 03:47 |
| GHSA-3HP8-6J24-M5GM | Duplicate Advisory: Camaleon CMS vulnerable to remote code execution through code injection (GHSL-2024-185) 已撤回 | 高危 | RubyGemscamaleon_cms | 已审查 | 2024-09-24 06:05 | 2025-05-24 04:02 |
| GHSA-VVF8-2H68-9475 | Duplicate Advisory: Keycloak Open Redirect vulnerability 已撤回 | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2024-09-20 02:30 | 2024-12-21 01:54 |
| GHSA-4XX7-2CX3-X473 | Duplicate Advisory: Keycloak SAML signature validation flaw 已撤回 | 中危 | Mavenorg.keycloak:keycloak-saml-core | 已审查 | 2024-09-20 02:30 | 2024-12-21 01:48 |
| GHSA-5HC5-FXR9-5FRC | Duplicate Advisory: Mautic has insufficient authentication in upgrade flow 已撤回 | 高危 | Packagistmautic/core | 已审查 | 2024-09-19 08:31 | 2025-02-22 05:43 |
| GHSA-W73R-8MM4-CFVF CVE-2024-6582 | Withdrawn Advisory: Lunary Improper Authentication vulnerability 已撤回 | 高危 | npmlunary | 已审查 | 2024-09-14 02:31 | 2024-11-26 00:00 |
| GHSA-V6X6-4V4X-2FX9 CVE-2024-6862 | Withdrawn Advisory: Lunary Cross-Site Request Forgery (CSRF) vulnerability 已撤回 | 中危 | npm@lunary/backend+1 | 已审查 | 2024-09-14 02:31 | 2025-06-21 04:02 |
| GHSA-9JMP-J63G-8X6M CVE-2024-6867 | Withdrawn Advisory: Lunary information disclosure vulnerability 已撤回 | 中危 | npmlunary | 已审查 | 2024-09-14 02:31 | 2025-06-21 04:01 |
| GHSA-6P2Q-8QFQ-WQ7X CVE-2024-6087 | Withdrawn Advisory: Lunary improper access control vulnerability 已撤回 | 高危 | npmlunary | 已审查 | 2024-09-14 02:31 | 2025-06-21 04:01 |
| GHSA-J76J-RQWJ-JMVV | Duplicate Advisory: Keycloak Session Fixation vulnerability 已撤回 | 高危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2024-09-10 05:31 | 2024-12-21 01:50 |
| GHSA-57RH-GR4V-J5F6 | Duplicate Advisory: Keycloak Uses a Key Past its Expiration Date 已撤回 | 中危 | Mavenorg.keycloak:keycloak-core | 已审查 | 2024-09-10 05:31 | 2024-12-21 01:49 |
| GHSA-8WM9-24QG-M5QJ | Duplicate Advisory: Keycloak has a brute force login protection bypass 已撤回 | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2024-09-04 05:31 | 2024-09-18 06:22 |
| GHSA-G8H2-J9PM-4XX2 CVE-2024-40111 | Automad Cross-site Scripting vulnerability 已撤回 | 中危 | Packagistautomad/automad | 已审查 | 2024-08-24 05:30 | 2024-08-27 05:26 |
| GHSA-H27C-6XM3-MCQP CVE-2024-43403 | Withdrawn Advisory: Kanister vulnerable to cluster-level privilege escalation 已撤回 | 中危 | Gogithub.com/kanisterio/kanister | 已审查 | 2024-08-21 06:13 | 2024-11-26 04:50 |
| GHSA-Q83V-HQ3J-4PQ3 | Duplicate Advisory: Improper access control in Directus 已撤回 | 中危 | npmdirectus | 已审查 | 2024-08-15 14:32 | 2025-03-21 02:34 |