Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

4 advisories

Time-of-check Time-of-use (TOCTOU) Race Condition in league/flysystem Critical
CVE-2021-32708 was published for league/flysystem (Composer) Jun 29, 2021
stevenseeley
Jetty Utility Servlets ConcatServlet Double Decoding Information Disclosure Vulnerability Moderate
CVE-2021-28169 was published for org.eclipse.jetty:jetty-servlets (Maven) Jun 10, 2021
stevenseeley
Sandbox escape through template_object in smarty High
CVE-2021-26119 was published for smarty/smarty (Composer) Mar 2, 2021
stevenseeley
PHP Code Injection by malicious function name in smarty Critical
CVE-2021-26120 was published for smarty/smarty (Composer) Feb 26, 2021
stevenseeley
ProTip! Advisories are also available from the GraphQL API