docker.io/atlassian/jira-software:10.0.0 linux/amd64

docker.io/atlassian/jira-software:10.0.0 - Trivy安全扫描结果 扫描时间: 2025-02-12 17:43
全部漏洞信息
低危漏洞:33 中危漏洞:38 高危漏洞:8 严重漏洞:4

系统OS: ubuntu 24.04 扫描引擎: Trivy 扫描时间: 2025-02-12 17:43

docker.io/atlassian/jira-software:10.0.0 (ubuntu 24.04) (ubuntu)
低危漏洞:32 中危漏洞:18 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
libfreetype6 CVE-2025-23022 中危 2.13.2+dfsg-1build3 freetype: signed integer overflow in cf2_doFlex

漏洞详情: https://avd.aquasec.com/nvd/cve-2025-23022

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2025-01-10 15:15 修改: 2025-01-16 21:12

libgssapi-krb5-2 CVE-2024-26462 中危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libk5crypto3 CVE-2024-26462 中危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libkrb5-3 CVE-2024-26462 中危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libkrb5support0 CVE-2024-26462 中危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/kdc/ndr.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26462

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-05-14 15:09

libpam-modules CVE-2024-10041 中危 1.5.3-5ubuntu5.1 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam-modules CVE-2024-10963 中危 1.5.3-5ubuntu5.1 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10963

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-11-07 16:15 修改: 2024-11-11 18:15

libpam-modules-bin CVE-2024-10041 中危 1.5.3-5ubuntu5.1 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam-modules-bin CVE-2024-10963 中危 1.5.3-5ubuntu5.1 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10963

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-11-07 16:15 修改: 2024-11-11 18:15

libpam-runtime CVE-2024-10041 中危 1.5.3-5ubuntu5.1 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam-runtime CVE-2024-10963 中危 1.5.3-5ubuntu5.1 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10963

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-11-07 16:15 修改: 2024-11-11 18:15

libpam0g CVE-2024-10041 中危 1.5.3-5ubuntu5.1 pam: libpam: Libpam vulnerable to read hashed password

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10041

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-10-23 14:15 修改: 2024-12-18 10:15

libpam0g CVE-2024-10963 中危 1.5.3-5ubuntu5.1 pam: Improper Hostname Interpretation in pam_access Leads to Access Control Bypass

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-10963

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-11-07 16:15 修改: 2024-11-11 18:15

login CVE-2024-56433 中危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

passwd CVE-2024-56433 中危 1:4.13+dfsg1-4ubuntu3.2 shadow-utils: Default subordinate ID configuration in /etc/login.defs could lead to compromise

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56433

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-12-26 09:15 修改: 2024-12-26 09:15

python3-jinja2 CVE-2024-56201 中危 3.1.2-1ubuntu1.2 jinja2: Jinja has a sandbox breakout through malicious filenames

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56201

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-12-23 16:15 修改: 2025-01-08 16:15

python3-jinja2 CVE-2024-56326 中危 3.1.2-1ubuntu1.2 jinja2: Jinja has a sandbox breakout through indirect reference to format method

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-56326

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-12-23 16:15 修改: 2024-12-27 18:15

wget CVE-2021-31879 中危 1.21.4-1ubuntu4.1 wget: authorization header disclosure on redirect

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-31879

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2021-04-29 05:15 修改: 2022-05-13 20:52

binutils CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

libgcrypt20 CVE-2024-2236 低危 1.10.3-2build1 libgcrypt: vulnerable to Marvin Attack

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-2236

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-03-06 22:15 修改: 2024-11-12 18:15

libgprofng0 CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

binutils-common CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

libgssapi-krb5-2 CVE-2024-26458 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libgssapi-krb5-2 CVE-2024-26461 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

binutils-x86-64-linux-gnu CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

libk5crypto3 CVE-2024-26458 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libk5crypto3 CVE-2024-26461 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

coreutils CVE-2016-2781 低危 9.4-3ubuntu6 coreutils: Non-privileged session can escape to the parent session in chroot

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-2781

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2017-02-07 15:59 修改: 2023-11-07 02:32

libkrb5-3 CVE-2024-26458 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libkrb5-3 CVE-2024-26461 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

dirmngr CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libkrb5support0 CVE-2024-26458 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/rpc/pmap_rmt.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26458

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-12-06 21:15

libkrb5support0 CVE-2024-26461 低危 1.20.1-6ubuntu2.3 krb5: Memory leak at /krb5/src/lib/gssapi/krb5/k5sealv3.c

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26461

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2024-02-29 01:44 修改: 2024-08-14 16:35

gnupg CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gnupg-utils CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpg CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpg-agent CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpgconf CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpgsm CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

gpgv CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

keyboxd CVE-2022-3219 低危 2.4.4-2ubuntu17 gnupg: denial of service issue (resource consumption) using compressed packets

漏洞详情: https://avd.aquasec.com/nvd/cve-2022-3219

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2023-02-23 20:15 修改: 2023-05-26 16:31

libsframe1 CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

libssl3t64 CVE-2024-41996 低危 3.0.13-0ubuntu3.4 openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41996

镜像层: sha256:4b7c01ed0534d4f9be9cf97d068da1598c6c20b26cb6134fad066defdb6d541d

发布日期: 2024-08-26 06:15 修改: 2024-08-26 16:35

locales CVE-2016-20013 低危 2.39-0ubuntu8.4

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

libbinutils CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

openssl CVE-2024-41996 低危 3.0.13-0ubuntu3.4 openssl: remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-41996

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2024-08-26 06:15 修改: 2024-08-26 16:35

libc-bin CVE-2016-20013 低危 2.39-0ubuntu8.4

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

libc6 CVE-2016-20013 低危 2.39-0ubuntu8.4

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-20013

镜像层: sha256:3e9614e676f2e647233c42de8f9249b7a0a2027af5cc99992b2e184b126c43ed

发布日期: 2022-02-19 05:15 修改: 2022-03-03 16:43

libctf-nobfd0 CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

libctf0 CVE-2017-13716 低危 2.42-4ubuntu2.3 binutils: Memory leak with the C++ symbol demangler routine in libiberty

漏洞详情: https://avd.aquasec.com/nvd/cve-2017-13716

镜像层: sha256:479a1d8f9a9bc4d0bdbfddae8a7d3f07810aa39213c340f4978d161f93ce17a9

发布日期: 2017-08-28 21:29 修改: 2019-10-03 00:03

Java (jar)
低危漏洞:1 中危漏洞:20 高危漏洞:8 严重漏洞:4
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
org.apache.avro:avro CVE-2024-47561 严重 1.11.3 1.11.4 apache-avro: Schema parsing may trigger Remote Code Execution (RCE)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47561

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-10-03 11:15 修改: 2024-10-21 09:15

org.apache.tomcat:tomcat-catalina CVE-2024-52316 严重 9.0.91 9.0.96, 10.1.30, 11.0.1 tomcat: Apache Tomcat: Authentication bypass when using Jakarta Authentication API

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-52316

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-18 12:15 修改: 2024-11-18 17:11

org.springframework.security:spring-security-web CVE-2024-38821 严重 5.8.13 5.7.13, 5.8.15, 6.2.7, 6.0.13, 6.1.11, 6.3.4 Spring-WebFlux: Authorization Bypass of Static Resources in WebFlux Applications

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38821

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-10-28 07:15 修改: 2024-10-28 13:58

org.springframework:spring-web CVE-2016-1000027 严重 5.3.37 6.0.0 spring: HttpInvokerServiceExporter readRemoteInvocation method untrusted java deserialization

漏洞详情: https://avd.aquasec.com/nvd/cve-2016-1000027

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2020-01-02 23:15 修改: 2023-04-20 09:15

com.google.protobuf:protobuf-java CVE-2024-7254 高危 3.21.9 3.25.5, 4.27.5, 4.28.2 protobuf: StackOverflow vulnerability in Protocol Buffers

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-7254

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-09-19 01:15 修改: 2024-12-13 14:15

org.apache.commons:commons-compress CVE-2024-25710 高危 1.22 1.26.0 commons-compress: Denial of service caused by an infinite loop for a corrupted DUMP file

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-25710

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-02-19 09:15 修改: 2024-03-07 17:15

com.thoughtworks.xstream:xstream CVE-2024-47072 高危 1.4.20 1.4.21 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47072

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-08 00:15 修改: 2024-11-08 19:01

org.apache.tomcat:tomcat-catalina CVE-2024-50379 高危 9.0.91 11.0.2, 10.1.34, 9.0.98 tomcat: RCE due to TOCTOU issue in JSP compilation

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-50379

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-12-17 13:15 修改: 2025-01-03 12:15

org.apache.velocity:velocity CVE-2020-13936 高危 1.6.4-atlassian-36 velocity: arbitrary code execution when attacker is able to modify templates

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-13936

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2021-03-10 08:15 修改: 2023-11-07 03:17

org.jdom:jdom CVE-2021-33813 高危 1.1.3-atlassian-5 jdom: XXE allows attackers to cause a DoS via a crafted HTTP request

漏洞详情: https://avd.aquasec.com/nvd/cve-2021-33813

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2021-06-16 12:15 修改: 2023-11-07 03:35

com.thoughtworks.xstream:xstream CVE-2024-47072 高危 1.4.20 1.4.21 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47072

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-08 00:15 修改: 2024-11-08 19:01

com.thoughtworks.xstream:xstream CVE-2024-47072 高危 1.4.20 1.4.21 com.thoughtworks.xstream: XStream is vulnerable to a Denial of Service attack due to stack overflow from a manipulated binary input stream

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47072

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-08 00:15 修改: 2024-11-08 19:01

io.netty:netty-common CVE-2024-47535 中危 4.1.108.Final 4.1.115 netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-12 16:15 修改: 2024-11-13 17:01

io.netty:netty-common CVE-2024-47535 中危 4.1.111.Final 4.1.115 netty: Denial of Service attack on windows app using Netty

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47535

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-11-12 16:15 修改: 2024-11-13 17:01

org.apache.tomcat:tomcat-catalina CVE-2024-54677 中危 9.0.91 11.0.2, 10.1.34, 9.0.98 tomcat: Apache Tomcat: DoS in examples web application

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-54677

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-12-17 13:15 修改: 2024-12-18 17:15

com.squareup.okio:okio CVE-2023-3635 中危 1.17.2 3.4.0, 1.17.6 okio: GzipSource class improper exception handling

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-3635

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2023-07-12 19:15 修改: 2023-10-25 15:17

org.apache.velocity:velocity-tools CVE-2020-13959 中危 1.3 velocity: XSS in the default error page for VelocityView

漏洞详情: https://avd.aquasec.com/nvd/cve-2020-13959

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2021-03-10 08:15 修改: 2023-11-07 03:17

org.bouncycastle:bcprov-jdk18on CVE-2024-29857 中危 1.77 1.78 org.bouncycastle: Importing an EC certificate with crafted F2m parameters may lead to Denial of Service

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-29857

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-05-14 15:17 修改: 2024-12-06 14:15

org.bouncycastle:bcprov-jdk18on CVE-2024-30171 中危 1.77 1.78 bc-java: BouncyCastle vulnerable to a timing variant of Bleichenbacher (Marvin Attack)

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-30171

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-05-14 15:21 修改: 2024-08-19 18:35

org.bouncycastle:bcprov-jdk18on CVE-2024-30172 中危 1.77 1.78 org.bouncycastle:bcprov-jdk18on: Infinite loop in ED25519 verification in the ScalarUtil class

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-30172

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-05-14 15:21 修改: 2024-11-05 18:35

commons-httpclient:commons-httpclient CVE-2012-5783 中危 3.1-jenkins-3 4.0 jakarta-commons-httpclient: missing connection hostname check against X.509 certificate name

漏洞详情: https://avd.aquasec.com/nvd/cve-2012-5783

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2012-11-04 22:55 修改: 2021-04-23 17:28

org.owasp.antisamy:antisamy CVE-2023-43643 中危 1.6.8-atlassian-11 1.7.4 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-43643

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2023-10-09 14:15 修改: 2023-10-13 17:35

org.owasp.antisamy:antisamy CVE-2023-43643 中危 1.6.8-atlassian-11 1.7.4 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-43643

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2023-10-09 14:15 修改: 2023-10-13 17:35

org.owasp.antisamy:antisamy CVE-2024-23635 中危 1.6.8-atlassian-11 1.7.5 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23635

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-02-02 17:15 修改: 2024-02-10 01:38

org.owasp.antisamy:antisamy CVE-2024-23635 中危 1.6.8-atlassian-11 1.7.5 AntiSamy is a library for performing fast, configurable cleansing of H ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-23635

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-02-02 17:15 修改: 2024-02-10 01:38

org.springframework.ldap:spring-ldap-core CVE-2024-38829 中危 2.4.1 3.2.8, 2.4.4 spring-ldap: Spring LDAP sensitive data exposure for case-sensitive comparisons

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38829

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-12-04 21:15 修改: 2024-12-10 15:15

org.springframework.security:spring-security-core CVE-2024-38827 中危 5.8.13 5.7.14, 5.8.16, 6.0.14, 6.1.12, 6.2.8, 6.3.5 spring-security: authorization bypass for case sensitive comparisons

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38827

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-12-02 15:15 修改: 2024-12-02 15:15

org.apache.commons:commons-compress CVE-2023-42503 中危 1.22 1.24.0 apache-commons-compress: Denial of service via CPU consumption for malformed TAR file

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-42503

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2023-09-14 08:15 修改: 2024-02-21 21:27

org.springframework:spring-context CVE-2024-38820 中危 5.3.37 6.1.14 The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38820

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-10-18 06:15 修改: 2024-11-29 12:15

org.springframework:spring-expression CVE-2024-38808 中危 5.3.37 5.3.39 spring-expression: Denial of service when processing a specially crafted Spring Expression Language expression

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38808

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-08-20 08:15 修改: 2024-10-30 19:35

org.apache.commons:commons-compress CVE-2024-26308 中危 1.22 1.26.0 commons-compress: OutOfMemoryError unpacking broken Pack200 file

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-26308

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-02-19 09:15 修改: 2024-03-21 19:54

org.springframework:spring-web CVE-2024-38809 中危 5.3.37 5.3.38, 6.0.23, 6.1.12 org.springframework:spring-web: Spring Framework DoS via conditional HTTP request

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-38809

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-09-27 17:15 修改: 2024-09-30 12:45

org.bouncycastle:bcprov-jdk18on CVE-2024-34447 低危 1.77 1.78 org.bouncycastle: Use of Incorrectly-Resolved Name or Reference

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-34447

镜像层: sha256:ae6a6d37f25627c1ee9b025b33eacf4d4d5878b57dd2394310ec3200eb5b2cbd

发布日期: 2024-05-03 16:15 修改: 2024-06-14 13:15

Node.js (node-pkg)
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息