基础信息
项目名称:cncf/cnf-testsuite
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1716755130044170240/1716755130090307584
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Google Golang 资源管理错误漏洞 | MPS-2022-58307 | CVE-2022-41723 | 高危 | |
Google Go 权限许可和访问控制问题漏洞 | 权限管理不当 | MPS-2022-9049 | CVE-2022-29526 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
golang.org/x/net | v0.0.0-20201110031124-69a78807bb2b | 0.17.0 | 间接依赖 | 建议修复 |
golang.org/x/sys | v0.0.0-20201214210602-f9fddec55a1e | 0.1.0 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
BSD-3-Clause | 23 | 低 |
Apache-2.0 | 46 | 低 |
ISC | 1 | 低 |
MIT | 13 | 低 |
MPL-2.0 | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
github.com/Azure/azure-sdk-for-go | v40.6.0+incompatible | 间接依赖 | go |
libdl.so.2 | 间接依赖 | ||
golang.org/x/xerrors | v0.0.0-20200804184101-5ec99f83aff1 | 间接依赖 | go |
github.com/prometheus/client_golang | v1.9.0 | 间接依赖 | go |
google.golang.org/protobuf | v1.25.0 | 间接依赖 | go |
libcrypto.so.1.1 | 间接依赖 | ||
golang.org/x/term | v0.0.0-20201117132131-f5c789dd3221 | 间接依赖 | go |
github.com/davecgh/go-spew | v1.1.1 | 间接依赖 | go |
github.com/DataDog/datadog-go | v3.5.0+incompatible | 间接依赖 | go |
k8s.io/klog | v1.0.0 | 间接依赖 | go |
gopkg.in/DataDog/dd-trace-go.v1 | v1.28.0 | 间接依赖 | go |
k8s.io/api | v0.20.2 | 间接依赖 | go |
libc.so.6 | 间接依赖 | ||
github.com/form3tech-oss/jwt-go | v3.2.2+incompatible | 间接依赖 | go |
github.com/hashicorp/golang-lru | v0.5.4 | 间接依赖 | go |
libxml2 | 间接依赖 | ||
github.com/golang/groupcache | v0.0.0-20200121045136-8c9f03a8e57e | 间接依赖 | go |
github.com/Azure/go-autorest/autorest/date | v0.3.0 | 间接依赖 | go |
github.com/opentracing-contrib/go-observer | v0.0.0-20170622124052-a52f23424492 | 间接依赖 | go |
gopkg.in/inf.v0 | v0.9.1 | 间接依赖 | go |
github.com/go-logr/logr | v0.2.0 | 间接依赖 | go |
golang.org/x/sys | v0.0.0-20201214210602-f9fddec55a1e | 间接依赖 | go |
github.com/modern-go/reflect2 | v1.0.1 | 间接依赖 | go |
libgcc_s.so.1 | 间接依赖 | ||
github.com/Azure/go-autorest/autorest/azure/cli | v0.4.2 | 间接依赖 | go |
cloud.google.com/go | v0.56.0 | 间接依赖 | go |
github.com/farsightsec/golang-framestream | v0.3.0 | 间接依赖 | go |
github.com/miekg/dns | v1.1.38 | 间接依赖 | go |
libevent | 间接依赖 | ||
github.com/cespare/xxhash/v2 | v2.1.1 | 间接依赖 | go |
sigs.k8s.io/yaml | v1.2.0 | 间接依赖 | go |
github.com/prometheus/client_model | v0.2.0 | 间接依赖 | go |
github.com/modern-go/concurrent | v0.0.0-20180306012644-bacd9c7ef1dd | 间接依赖 | go |
github.com/jmespath/go-jmespath | v0.4.0 | 间接依赖 | go |
golang.org/x/text | v0.3.4 | 间接依赖 | go |
golang.org/x/oauth2 | v0.0.0-20200107190931-bf48bf16ab8d | 间接依赖 | go |
github.com/dimchansky/utfbom | v1.1.1 | 间接依赖 | go |
github.com/imdario/mergo | v0.3.9 | 间接依赖 | go |
libssl.so.1.1 | 间接依赖 | ||
github.com/Azure/go-autorest/autorest/azure/auth | v0.5.7 | 间接依赖 | go |
github.com/philhofer/fwd | v1.0.0 | 间接依赖 | go |
github.com/google/uuid | v1.1.2 | 间接依赖 | go |
gopkg.in/yaml.v2 | v2.3.0 | 间接依赖 | go |
google.golang.org/genproto | v0.0.0-20200526211855-cb27e3aa2013 | 间接依赖 | go |
k8s.io/client-go | v0.20.2 | 间接依赖 | go |
github.com/flynn/go-shlex | v0.0.0-20150515145356-3f9db97f8568 | 间接依赖 | go |
sigs.k8s.io/structured-merge-diff/v4 | v4.0.2 | 间接依赖 | go |
github.com/prometheus/common | v0.15.0 | 间接依赖 | go |
libpthread.so.0 | 间接依赖 | ||
github.com/Azure/go-autorest/tracing | v0.6.0 | 间接依赖 | go |
github.com/beorn7/perks | v1.0.1 | 间接依赖 | go |
github.com/opentracing/opentracing-go | v1.2.0 | 间接依赖 | go |
github.com/aws/aws-sdk-go | v1.37.10 | 间接依赖 | go |
github.com/googleapis/gax-go/v2 | v2.0.5 | 间接依赖 | go |
github.com/google/go-cmp | v0.5.2 | 间接依赖 | go |
google.golang.org/grpc | v1.29.1 | 间接依赖 | go |
libm.so.6 | 间接依赖 | ||
github.com/prometheus/procfs | v0.2.0 | 间接依赖 | go |
github.com/dnstap/golang-dnstap | v0.4.0 | 间接依赖 | go |
github.com/tinylib/msgp | v1.1.2 | 间接依赖 | go |
github.com/gogo/protobuf | v1.3.1 | 间接依赖 | go |
github.com/golang/protobuf | v1.4.3 | 间接依赖 | go |
go.uber.org/atomic | v1.6.0 | 间接依赖 | go |
github.com/grpc-ecosystem/grpc-opentracing | v0.0.0-20180507213350-8e809c8a8645 | 间接依赖 | go |
github.com/coredns/caddy | v1.1.0 | 间接依赖 | go |
golang.org/x/net | v0.0.0-20201110031124-69a78807bb2b | 间接依赖 | go |
google.golang.org/api | v0.29.0 | 间接依赖 | go |
golang.org/x/crypto | v0.0.0-20201221181555-eec23a3978ad | 间接依赖 | go |
github.com/Azure/go-autorest/logger | v0.2.1 | 间接依赖 | go |
libyaml | 间接依赖 | ||
github.com/openzipkin-contrib/zipkin-go-opentracing | v0.4.5 | 间接依赖 | go |
github.com/infobloxopen/go-trees | v0.0.0-20190313150506-2af4e13f9062 | 间接依赖 | go |
github.com/json-iterator/go | v1.1.10 | 间接依赖 | go |
github.com/mitchellh/go-homedir | v1.1.0 | 间接依赖 | go |
go.uber.org/zap | v1.14.1 | 间接依赖 | go |
github.com/googleapis/gnostic | v0.4.1 | 间接依赖 | go |
k8s.io/apimachinery | v0.20.2 | 间接依赖 | go |
golang.org/x/time | v0.0.0-20200630173020-3af7569d3a1e | 间接依赖 | go |
github.com/spf13/pflag | v1.0.5 | 间接依赖 | go |
github.com/openzipkin/zipkin-go | v0.2.2 | 间接依赖 | go |
go.opencensus.io | v0.22.3 | 间接依赖 | go |
github.com/Azure/go-autorest/autorest/adal | v0.9.13 | 间接依赖 | go |
libpcre.so.3 | 间接依赖 | ||
github.com/coreos/go-systemd/v22 | v22.0.0 | 间接依赖 | go |
k8s.io/klog/v2 | v2.4.0 | 间接依赖 | go |
github.com/google/gofuzz | v1.1.0 | 间接依赖 | go |
github.com/Azure/go-autorest/autorest/to | v0.2.0 | 间接依赖 | go |
github.com/matttproud/golang_protobuf_extensions | v1.0.1 | 间接依赖 | go |
ld-linux-x86-64.so.2 | 间接依赖 | ||
libz.so.1 | 间接依赖 | ||
go.uber.org/multierr | v1.5.0 | 间接依赖 | go |
github.com/Azure/go-autorest/autorest | v0.11.18 | 间接依赖 | go |
k8s.io/utils | v0.0.0-20201110183641-67b214c5f920 | 间接依赖 | go |
go.etcd.io/etcd | v0.5.0-alpha.5.0.20200306183522-221f0cc107cb | 间接依赖 | go |