ghcr.io/gethomepage/homepage:v0.10.8 linux/amd64

ghcr.io/gethomepage/homepage:v0.10.8 - Trivy安全扫描结果 扫描时间: 2025-01-06 22:28
全部漏洞信息
低危漏洞:1 中危漏洞:5 高危漏洞:2 严重漏洞:1

系统OS: alpine 3.21.0 扫描引擎: Trivy 扫描时间: 2025-01-06 22:28

ghcr.io/gethomepage/homepage:v0.10.8 (alpine 3.21.0) (alpine)
低危漏洞:0 中危漏洞:0 高危漏洞:0 严重漏洞:0
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
Node.js (node-pkg)
低危漏洞:1 中危漏洞:5 高危漏洞:2 严重漏洞:1
软件包 漏洞 安全状态 安装版本 修复版本 漏洞信息
jsonpath-plus CVE-2024-21534 严重 0.19.0 10.0.7 jsonpath-plus: Remote Code Execution in jsonpath-plus via Improper Input Sanitization

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21534

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2024-10-11 13:15 修改: 2024-11-18 11:15

cross-spawn CVE-2024-21538 高危 7.0.3 7.0.5, 6.0.6 cross-spawn: regular expression denial of service

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-21538

镜像层: sha256:dbf4e3ba24d513094700faacf21482f78570648563d1f001e75bc456a3e25d7a

发布日期: 2024-11-08 05:15 修改: 2024-11-19 14:15

next CVE-2024-51479 高危 12.3.4 14.2.15 next.js: next: authorization bypass in Next.js

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-51479

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2024-12-17 19:15 修改: 2024-12-17 19:15

nanoid CVE-2024-55565 中危 3.3.7 5.0.9, 3.3.8 nanoid: nanoid mishandles non-integer values

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-55565

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2024-12-09 02:15 修改: 2024-12-12 19:15

next CVE-2024-47831 中危 12.3.4 14.2.7 next.js: Next.js image optimization has Denial of Service condition

漏洞详情: https://avd.aquasec.com/nvd/cve-2024-47831

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2024-10-14 18:15 修改: 2024-11-08 15:39

postcss CVE-2023-44270 中危 8.4.14 8.4.31 PostCSS: Improper input validation in PostCSS

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-44270

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2023-09-29 22:15 修改: 2023-10-10 17:19

request CVE-2023-28155 中危 2.88.2 The Request package through 2.88.1 for Node.js allows a bypass of SSRF ...

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-28155

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2023-03-16 15:15 修改: 2024-08-02 13:15

tough-cookie CVE-2023-26136 中危 2.5.0 4.1.3 tough-cookie: prototype pollution in cookie memstore

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-26136

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2023-07-01 05:15 修改: 2024-06-21 19:15

next CVE-2023-46298 低危 12.3.4 13.4.20-canary.13 Next.js missing cache-control header may lead to CDN caching empty reply

漏洞详情: https://avd.aquasec.com/nvd/cve-2023-46298

镜像层: sha256:9c7a0e575443637afefd67431d17de8391610d9a489ab913f74d4d366370f5a1

发布日期: 2023-10-22 03:15 修改: 2023-10-28 03:30