检索 GitHub Advisory Database 中的已审查与未审查安全公告。
| 公告编号 | 摘要 | 级别 | 生态 / 软件包 | 审查状态 | 发布时间 | 修改时间 |
|---|---|---|---|---|---|---|
| GHSA-XM99-6PV5-Q363 CVE-2022-29583 | Disputed: OS Command injection in github.com/kardianos/service 已撤回 | 高危 | Gogithub.com/kardianos/service | 已审查 | 2022-04-23 08:03 | 2023-05-25 01:39 |
当前筛选结果 998 条 · 时间按北京时间显示
| GHSA-7GC6-QH9X-W6H8 CVE-2022-1365 |
Withdrawn Advisory: Incorrect Authorization in cross-fetch 已撤回 |
| 中危 |
npmcross-fetch |
| 已审查 |
| 2022-04-17 08:00 |
| 2025-10-09 03:22 |
| GHSA-86R3-4GQ8-XW8Q CVE-2021-43503 | Remote Code Execution in Laravel 已撤回 | 严重 | Packagistlaravel/laravel | 已审查 | 2022-04-09 08:00 | 2022-08-23 00:34 |
| GHSA-CHR6-386Q-4M3V | Duplicate Advisory: Stored Cross-site Scripting vulnerability in Jenkins Folder-based Authorization Strategy Plugin 已撤回 | 中危 | Mavenio.jenkins.plugins:folder-auth | 已审查 | 2022-03-16 08:00 | 2026-02-04 01:38 |
| GHSA-65F3-3278-7M65 | Duplicate Advisory: Improper Authorization in Gogs 已撤回 | 高危 | Gogogs.io/gogs | 已审查 | 2022-03-12 08:00 | 2023-07-01 06:10 |
| GHSA-29VR-79W7-P649 CVE-2021-44597 | Duplicate Advisory: Incorrect Authorization in Gerapy 已撤回 | 严重 | PyPIgerapy | 已审查 | 2022-03-11 08:02 | 2023-08-01 04:36 |
| GHSA-H2G5-2RHX-FFGJ CVE-2022-24727 | Duplicate Advisory: Command injection in Weblate 已撤回 | 高危 | PyPIWeblate | 已审查 | 2022-03-05 08:00 | 2026-01-24 06:29 |
| GHSA-M6GG-86C6-GFR9 CVE-2022-23710 | Withdrawn: Cross-site Scripting in Kibana 已撤回 | 中危 | Mavenorg.elasticsearch:elasticsearch | 已审查 | 2022-03-04 08:00 | 2023-03-16 03:19 |
| GHSA-9R5X-FJV3-Q6H4 | Duplicate Advisory: Incorrect Access Control in github.com/nats-io/jwt and github.com/nats-io/nats-server/v2 已撤回 | 高危 | Gogithub.com/nats-io/jwt+2 | 已审查 | 2022-02-15 09:57 | 2024-05-21 22:35 |
| GHSA-M658-P24X-P74R | Duplicate Advisory: TLS certificate validation error in mellium.im/xmpp 已撤回 | 中危 | Gomellium.im/xmpp | 已审查 | 2022-02-12 08:00 | 2024-05-21 05:04 |
| GHSA-76WF-9VGP-PJ7W | Duplicate Advisory: Unencrypted md5 plaintext hash in metadata in AWS S3 Crypto SDK for golang 已撤回 | 中危 | Gogithub.com/aws/aws-sdk-go | 已审查 | 2022-02-12 07:26 | 2026-02-04 03:37 |
| GHSA-WFVQ-P7QF-VV64 | Duplicate advisory: swift-nio-http2 vulnerable to denial of service via mishandled HPACK variable length integer encoding 已撤回 | 高危 | SwiftURLgithub.com/apple/swift-nio-http2 | 已审查 | 2022-02-11 08:00 | 2023-06-20 00:54 |
| GHSA-PV7R-9VJG-G3F9 | Duplicate advisory: swift-nio-http2 vulnerable to denial of service via invalid HTTP/2 HEADERS frame length 已撤回 | 高危 | SwiftURLgithub.com/apple/swift-nio-http2 | 已审查 | 2022-02-11 08:00 | 2023-06-20 01:00 |
| GHSA-GPGX-WHWH-R297 | Duplicate advisory: swift-nio-http2 vulnerable to denial of service via ALTSVC or ORIGIN frames 已撤回 | 高危 | SwiftURLgithub.com/apple/swift-nio-http2 | 已审查 | 2022-02-11 08:00 | 2023-06-20 00:50 |
| GHSA-6HR9-4692-FCH9 CVE-2020-7624 | Withdrawn Advisory: OS Command Injection in effect 已撤回 | 严重 | npmeffect | 已审查 | 2022-02-11 07:45 | 2024-06-05 02:24 |
| GHSA-GC58-V8H3-X2GR CVE-2020-8022 | Incorrect Default Permissions in Apache Tomcat 已撤回 | 高危 | Mavenorg.apache.tomcat:tomcat | 已审查 | 2022-02-10 07:01 | 2024-07-11 01:24 |
| GHSA-9CHX-2VQW-8VQ5 CVE-2022-23409 | Duplicate Advisory: Path Traversal in the Logs plugin for Craft CMS 已撤回 | 中危 | Packagistether/logs | 已审查 | 2022-02-01 08:01 | 2026-01-24 06:41 |
| GHSA-CVP7-C586-CMF4 CVE-2022-0329 | Withdrawn: Code Injection in loguru 已撤回 | 低危 | PyPIloguru | 已审查 | 2022-01-29 06:01 | 2022-02-01 23:17 |
| GHSA-7VVQ-7R29-5VG3 CVE-2022-0177 | Cross site scripting in three.js 已撤回 | 高危 | npmthree | 已审查 | 2022-01-28 00:00 | 2022-01-29 02:32 |
| GHSA-FM93-FHH2-CG2C | Duplicate Advisory: Prototype Pollution in min-dash 已撤回 | 高危 | npmmin-dash | 已审查 | 2022-01-27 22:21 | 2025-07-19 03:44 |
| GHSA-77RM-9X9H-XJ3G CVE-2021-22570 | Withdrawn Advisory: NULL Pointer Dereference in Protocol Buffers 已撤回 | 高危 | Gocom.google.protobuf:protobuf-java+4 | 已审查 | 2022-01-27 08:01 | 2025-08-26 06:36 |
| GHSA-QPW2-XCHM-655Q | Out-of-Bounds read in stringstream 已撤回 | 中危 | npmstringstream | 已审查 | 2022-01-07 04:31 | 2021-05-05 04:42 |
| GHSA-Q6GQ-997W-F55G CVE-2020-16845 | Withdrawn Advisory: Infinite loop in xz 已撤回 | 高危 | Gogithub.com/ulikunitz/xz | 已审查 | 2021-12-17 03:16 | 2025-10-15 03:37 |
| GHSA-74R6-GRJ9-8RQ6 | Duplicate Advisory: Remote Code Execution in AjaxNetProfessional 已撤回 | 严重 | NuGetAjaxNetProfessional | 已审查 | 2021-12-16 23:27 | 2026-02-04 01:39 |
| GHSA-GXJJ-F44V-QM94 | Open Redirect in Flask-Security-Too 已撤回 | 低危 | PyPIFlask-Security-Too | 已审查 | 2021-12-15 02:14 | 2021-12-15 02:14 |