Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

10 advisories

Loading
Improper hashing in enrocrypt High
CVE-2021-39182 was published for enrocrypt (pip) Nov 10, 2021
Mattermost Server uses weak hashing for OAuth, email verification tokens and invitations High
CVE-2017-18917 was published for github.com/mattermost/mattermost-server (Go) May 24, 2022
Reversible One-Way Hash in io.github.javaezlib:JavaEZ High
CVE-2022-29249 was published for io.github.javaezlib:JavaEZ (Maven) May 25, 2022
Whole-script approval in Jenkins Script Security Plugin vulnerable to SHA-1 collisions High
CVE-2022-45379 was published for org.jenkins-ci.plugins:script-security (Maven) Nov 16, 2022
NotMyFault
Credited to NotMyFault
Duplicate Advisory: EVE Doesn't Measure Config Partition From 2 Fronts High
GHSA-5jvg-8j6f-vpmc was published for github.com/lf-edge/eve (Go) Sep 20, 2023 withdrawn
Duplicate Advisory: EVE Seals Vault Key With SHA1 PCRs High
GHSA-h929-fvvp-882c was published for github.com/lf-edge/eve (Go) Sep 20, 2023 withdrawn
Beego privilege escalation vulnerability High
CVE-2024-40465 was published for github.com/beego/beego/v2 (Go) Jul 31, 2024
ProTip! Advisories are also available from the GraphQL API