检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-8G9C-28FC-MCX2 | Duplicate Advisory: Microsoft Identity Denial of service vulnerability 已撤回 | 中危 | NuGetMicrosoft.IdentityModel.JsonWebTokens+1 | 已审查 | 2024-01-10 02:28 | 2024-04-16 03:42 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-V444-JGGX-6V7F |
Duplicate Advisory: Race Condition leading to logging errors 已撤回 |
| 低危 |
RubyGemsaudited |
| 已审查 |
| 2024-01-05 05:30 |
| 2024-01-05 23:27 |
| GHSA-QWF7-RV77-FCR3 | Duplicate Advisory: Malicious URL drafting attack against iodines static file server may allow path traversal 已撤回 | 低危 | RubyGemsiodine | 已审查 | 2024-01-05 05:30 | 2024-01-05 23:28 |
| GHSA-G47J-3M2M-74QV | Duplicate Advisory: httparty has multipart/form-data request tampering vulnerability 已撤回 | 中危 | RubyGemshttparty | 已审查 | 2024-01-05 05:30 | 2026-01-08 05:33 |
| GHSA-C2V4-CHX5-VFF6 | Duplicate Advisory: Integer overflow in cmark-gfm table parsing extension leads to heap memory corruption 已撤回 | 高危 | RubyGemscommonmarker | 已审查 | 2024-01-05 05:30 | 2024-01-05 23:31 |
| GHSA-4MVM-XH8J-FV27 | Duplicate Advisory: govuk_tech_docs vulnerable to unescaped HTML on search results page 已撤回 | 低危 | RubyGemsgovuk_tech_docs | 已审查 | 2024-01-05 05:30 | 2024-01-05 23:28 |
| GHSA-4553-HQ82-8654 | Duplicate Advisory: encoded_id-rails potential DOS vulnerability due to URIs with extremely long encoded IDs 已撤回 | 高危 | RubyGemsencoded_id-rails | 已审查 | 2024-01-05 05:30 | 2024-01-05 23:25 |
| GHSA-VFXF-76HV-V4W4 | Withdrawn Advisory: User-provided environment values allow execution on macOS agents 已撤回 | 高危 | Gogithub.com/gravitational/teleport | 已审查 | 2024-01-04 05:30 | 2024-09-07 05:40 |
| GHSA-C9V7-WMWJ-VF6X | Withdrawn Advisory: SFTP is possible on the Proxy server for any user with SFTP access 已撤回 | 高危 | Gogithub.com/gravitational/teleport | 已审查 | 2024-01-04 05:29 | 2024-09-07 05:40 |
| GHSA-76CC-P55W-63G3 | Withdrawn Advisory: Teleport Access List owners can escalate their privileges 已撤回 | 严重 | Gogithub.com/gravitational/teleport | 已审查 | 2024-01-04 05:29 | 2024-09-07 05:40 |
| GHSA-HW4X-MCX5-9Q36 | Withdrawn Advisory: Teleport Proxy and Teleport Agents: SSRF to arbitrary hosts is possible from low privileged users 已撤回 | 严重 | Gogithub.com/gravitational/teleport | 已审查 | 2024-01-04 05:28 | 2024-09-07 05:40 |
| GHSA-WXJ2-777F-VXMF | Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE plugins 已撤回 | 中危 | npmtinymce | 已审查 | 2024-01-04 02:30 | 2024-01-04 06:26 |
| GHSA-Q5PP-5Q2H-G8RV | Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE 已撤回 | 中危 | npmtinymce | 已审查 | 2024-01-04 02:30 | 2024-01-04 06:27 |
| GHSA-HF3R-VMRV-7W29 | Duplicate Advisory: Denial of service in CBOR library 已撤回 | 高危 | NuGetPeterO.Cbor | 已审查 | 2024-01-04 02:30 | 2024-01-04 06:28 |
| GHSA-GJHC-6XM7-MC8Q | Duplicate Advisory: Cross-site scripting vulnerability in TinyMCE 已撤回 | 中危 | npmtinymce | 已审查 | 2024-01-04 02:30 | 2024-01-04 06:27 |
| GHSA-8RFX-6MR3-5JH3 | Duplicate Advisory: Improper Handling of Exceptional Conditions in Newtonsoft.Json 已撤回 | 高危 | NuGetNewtonsoft.Json | 已审查 | 2024-01-04 02:30 | 2024-09-07 05:37 |
| GHSA-QPHF-W3CQ-JPMX CVE-2023-50570 | IPAddress Infinite Loop vulnerability (Disputed) 已撤回 | 中危 | Mavencom.github.seancfoley:ipaddress | 已审查 | 2023-12-29 23:30 | 2024-01-13 01:47 |
| GHSA-3GJC-MP82-FJ4Q | Duplicate Advisory: TYPO3 Arbitrary File Read via Directory Traversal 已撤回 | 中危 | Packagisttypo3/cms-core | 已审查 | 2023-12-25 14:30 | 2024-02-14 03:07 |
| GHSA-RQXC-9P8H-XQGQ | Duplicate Advisory: ActiveAdmin vulnerable to CSV injection 已撤回 | 高危 | RubyGemsactiveadmin | 已审查 | 2023-12-24 14:30 | 2023-12-29 02:45 |
| GHSA-FPPH-MQC8-H6Q5 CVE-2023-7036 | Withdrawn Advisory: Unrestricted File Upload affecting automad 已撤回 | 中危 | Packagistautomad/automad | 已审查 | 2023-12-22 02:30 | 2024-08-21 01:31 |
| GHSA-7J9H-CH38-474R CVE-2023-7035 | Withdrawn Advisory: Stored Cross-site scripting affecting automad/automad 已撤回 | 低危 | Packagistautomad/automad | 已审查 | 2023-12-21 23:30 | 2024-08-27 02:23 |
| GHSA-MHPQ-9638-X6PW | Duplicate Advisory: Denial of service when decrypting attack controlled input in github.com/dvsekhvalnov/jose2go 已撤回 | 中危 | Gogithub.com/dvsekhvalnov/jose2go | 已审查 | 2023-12-21 04:31 | 2026-02-04 01:53 |
| GHSA-3P75-Q5CC-QMJ7 | Duplicate Advisory: Keycloak Open Redirect vulnerability 已撤回 | 中危 | Mavenorg.keycloak:keycloak-parent | 已审查 | 2023-12-19 08:30 | 2024-12-24 00:39 |
| GHSA-5968-QW33-H47J | Duplicate Advisory: Keycloak vulnerable to reflected XSS via wildcard in OIDC redirect_uri 已撤回 | 中危 | Mavenorg.keycloak:keycloak-services | 已审查 | 2023-12-15 08:31 | 2023-12-19 03:30 |
| GHSA-3M87-5598-2V4F CVE-2019-3826 | Withdrawn Advisory: Prometheus XSS Vulnerability 已撤回 | 中危 | Gogithub.com/prometheus/prometheus | 已审查 | 2023-12-14 05:26 | 2023-12-19 04:53 |