检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-3839-6R69-M497 | Duplicate Advisory: GoUtils's randomly-generated alphanumeric strings contain significantly less entropy than expected 已撤回 | 严重 | Gogithub.com/Masterminds/goutils | 已审查 | 2022-12-28 08:30 | 2026-01-24 06:51 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-27H2-HVPR-P74Q CVE-2022-23529 |
jsonwebtoken has insecure input validation in jwt.verify function 已撤回 |
| 高危 |
npmjsonwebtoken |
| 已审查 |
| 2022-12-22 11:31 |
| 2023-01-28 05:51 |
| GHSA-54R5-WR8X-X5V3 | Duplicate Advisory: Apiman has insufficient checks for read permissions 已撤回 | 高危 | Mavenio.apiman:apiman-manager-api-rest-impl | 已审查 | 2022-12-20 08:30 | 2024-10-08 05:00 |
| GHSA-9QCM-FQJ9-93M4 | Duplicate Advisory: .NET Framework Remote Code Execution Vulnerability. 已撤回 | 高危 | NuGetMicrosoft.WindowsDesktop.App.Runtime.win-x64 | 已审查 | 2022-12-14 05:30 | 2023-11-11 06:06 |
| GHSA-Q7JC-V6F2-Q9JR | Duplicate Advisory: Resque Scheduler Reflected XSS In Delayed Jobs View 已撤回 | 中危 | RubyGemsresque-scheduler | 已审查 | 2022-12-13 23:30 | 2023-12-21 02:21 |
| GHSA-VC9X-GMMR-P7JJ CVE-2021-4243 | Duplicate advisory: @claviska/jquery-minicolors vulnerable to Cross-site Scripting 已撤回 | 中危 | npm@claviska/jquery-minicolors | 已审查 | 2022-12-12 23:30 | 2023-02-22 08:11 |
| GHSA-7VX2-5349-QJ99 CVE-2022-46464 | Withdrawn: ConcreteCMS vulnerable to Xpath injection attacks 已撤回 | 高危 | Packagistconcrete5/concrete5 | 已审查 | 2022-12-06 08:30 | 2023-06-07 02:32 |
| GHSA-R4JG-5V89-9V62 CVE-2022-39390 | Withdrawn: Octocat.js vulnerable to code injection 已撤回 | 高危 | npmoctocat.js | 已审查 | 2022-11-09 04:48 | 2022-11-10 06:35 |
| GHSA-Q4QM-FV7M-8RF7 CVE-2022-3772 | Duplicate Advisory: Cross-Site Request Forgery in easyii CMS 已撤回 | 高危 | Packagistnoumo/easyii | 已审查 | 2022-11-01 03:00 | 2024-04-26 05:23 |
| GHSA-9CHR-4FJH-5RGW CVE-2022-3704 | Cross-site Scripting in actionpack 已撤回 | 低危 | RubyGemsactionpack | 已审查 | 2022-10-27 20:00 | 2023-01-24 04:44 |
| GHSA-X58J-J539-W8MV CVE-2021-46849 | Duplicate Advisory: Improper Restriction of XML External Entity Reference in pikepdf 已撤回 | 严重 | PyPIpikepdf | 已审查 | 2022-10-25 03:00 | 2023-08-04 06:54 |
| GHSA-W596-4WVX-J9J6 CVE-2022-42969 | Withdrawn Advisory: ReDoS in py library when used with subversion 已撤回 | 高危 | PyPIpy | 已审查 | 2022-10-16 20:00 | 2026-05-30 04:49 |
| GHSA-9PGH-QQPF-7WQJ CVE-2022-37616 | Withdrawn: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @xmldom/xmldom and xmldom 已撤回 | 严重 | npm@xmldom/xmldom+1 | 已审查 | 2022-10-12 04:42 | 2022-11-09 03:35 |
| GHSA-WRX5-RP7M-MM49 CVE-2022-41852 | Withdrawn: CVE Rejected: JXPath vulnerable to remote code execution when interpreting untrusted XPath expressions 已撤回 | 严重 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2023-03-07 06:41 |
| GHSA-MQXP-CJR9-C5JM CVE-2022-40160 | JXPath Out-of-bounds Write vulnerability 已撤回 | 中危 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2022-11-17 05:12 |
| GHSA-MF2H-6MG2-PX9X CVE-2022-40158 | JXPath Out-of-bounds Write vulnerability 已撤回 | 中危 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2022-11-11 06:39 |
| GHSA-HW4Q-585G-F92X CVE-2022-40161 | JXPath Out-of-bounds Write vulnerability 已撤回 | 中危 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2022-11-11 06:39 |
| GHSA-C7MC-Q43H-5672 CVE-2022-40157 | JXPath Out-of-bounds Write vulnerability 已撤回 | 中危 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2022-11-11 06:39 |
| GHSA-99JC-V8QM-WJVV CVE-2022-40159 | JXPath Out-of-bounds Write vulnerability 已撤回 | 中危 | Mavencommons-jxpath:commons-jxpath | 已审查 | 2022-10-07 02:52 | 2022-11-11 06:39 |
| GHSA-5C6Q-F783-H888 | Duplicate Advisory: AWS Redshift JDBC Driver fails to validate class type during object instantiation 已撤回 | 高危 | Mavencom.amazon.redshift:redshift-jdbc42 | 已审查 | 2022-09-30 08:00 | 2024-10-08 04:58 |
| GHSA-FV22-XP26-MM9W CVE-2022-40153 | Denial of Service due to parser crash 已撤回 | 高危 | Mavencom.fasterxml.woodstox:woodstox-core | 已审查 | 2022-09-17 08:00 | 2022-12-06 21:40 |
| GHSA-9FWF-46G9-45RX CVE-2022-40154 | Denial of Service via stack overflow 已撤回 | 低危 | Mavencom.fasterxml.woodstox:woodstox-core | 已审查 | 2022-09-17 08:00 | 2022-12-06 21:41 |
| GHSA-5HC5-C3M9-8VCJ CVE-2022-40155 | Denial of Service via stack overflow 已撤回 | 低危 | Mavencom.fasterxml.woodstox:woodstox-core | 已审查 | 2022-09-17 08:00 | 2022-12-06 21:41 |
| GHSA-4RV7-WJ6M-6C6R CVE-2022-40156 | Denial of Service due to parser crash 已撤回 | 低危 | Mavencom.fasterxml.woodstox:woodstox-core | 已审查 | 2022-09-17 08:00 | 2022-12-06 21:39 |
| GHSA-3MQ5-FQ9H-GJ7J | Duplicate Advisory: Denial of Service due to parser crash 已撤回 | 低危 | Mavencom.thoughtworks.xstream:xstream | 已审查 | 2022-09-17 08:00 | 2023-03-04 07:04 |