🚨 最新安全公告
- 🟠 GHSA-pwpj-p52h-q484 [high] (2026-06-23)
Snipe-IT API Vulnerable to Cross-Tenant Accessory Injection
- 🟢 GHSA-6mmj-jhqj-6c6q [low] (2026-06-23)
Snipe-IT's S3 signature image retrieval lacks authorization before temporary URL
- 🟢 GHSA-x667-r589-43m7 [low] (2026-06-23)
Snipe-IT has Improper Authorization in File Deletion (IDOR)
- ⚪ GHSA-hf68-g98v-wp9g [medium] (2026-06-23)
Snipe-IT Vulnerable to Privilege Escalation via Missing admin Permission Check in User Creation
- ⚪ GHSA-33g4-646g-qwmm [medium] (2026-06-23)
Snipe-IT has Multi-Tenancy Bypass via Bulk Asset Update
- ⚪ GHSA-6x4j-8954-5hxm [medium] (2026-06-23)
Snipe-IT has a 2FA reset privilege bypass
- ⚪ GHSA-p68w-rgmg-3c2v [medium] (2026-06-23)
Snipe-IT Vulnerable to User Account Escalation via CSV Import
- ⚪ GHSA-w2j7-f3c6-g8cw [medium] (2026-06-23)
Flask-Security has an Open Redirect issue
- ⚪ GHSA-mr8g-2mj4-pcq2 [medium] (2026-06-23)
Snipe-IT's TOTP is Brute-Forceable Due to Missing Rate Limiting on POST /two-factor
- ⚪ GHSA-8c6h-7g6x-m5x4 [medium] (2026-06-23)
phpMyFAQ: Missing userHasPermission() in 4 API write endpoints (CVE-2026-24421 Incomplete Fix)
📡 数据来源: GitHub Security Advisories · 由 PingSec 安全日报自动生成