Cocolabs-SAS/cocorico 软件分析报告

基础信息

项目名称:Cocolabs-SAS/cocorico

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1716759863609835520/1716759863685332992

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Sensio Labs Symfony Web profiler 跨站脚本漏洞 XSS MPS-2018-7925 CVE-2018-12040 中危
MongoDB信息泄露漏洞 日志敏感信息泄露 MPS-2021-24103 CVE-2021-32050 高危
Sensio Labs Symfony 信息泄露漏洞 未授权敏感信息泄露 MPS-2021-6575 CVE-2021-21424 中危
Guzzle 信息泄露漏洞 敏感数据的不恰当跨边界移除 MPS-2022-11072 CVE-2022-31042 高危
Guzzle 信息泄露漏洞 敏感数据的不恰当跨边界移除 MPS-2022-11073 CVE-2022-31043 高危
Guzzle 信息泄露漏洞 敏感数据的不恰当跨边界移除 MPS-2022-11120 CVE-2022-31090 高危
Guzzle 信息泄露漏洞 未授权敏感信息泄露 MPS-2022-11121 CVE-2022-31091 高危
doctrine/orm 存在SQL注入漏洞 SQL注入 MPS-2022-14191 中危
Sensio Labs Twig 代码代码注入漏洞 代码注入 MPS-2022-2041 CVE-2022-23614 严重
PSR-7 Message Implementation 验证错误漏洞 对数据真实性的验证不充分 MPS-2022-3742 CVE-2022-24775 高危
Sensio Labs Symfony 授权问题漏洞 授权机制不恰当 MPS-2022-3861 CVE-2022-24894 高危
Sensio Labs Symfony 授权问题漏洞 会话固定 MPS-2022-3862 CVE-2022-24895 高危
Sensio Labs Twig路径遍历漏洞 路径遍历 MPS-2022-58285 CVE-2022-39261 高危
Guzzle信息泄露漏洞 在信任Cookie未进行验证与完整性检查 MPS-2022-8649 CVE-2022-29248 高危
PSR-7 Message Implementation 安全漏洞 解释冲突 MPS-2023-9403 CVE-2023-29197 高危
Laminas Project diactoros 拒绝服务漏洞 拒绝服务 MPS-2023-9897 CVE-2023-29530 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
twig/twig v2.12.3 3.4.3 间接依赖 强烈建议修复
guzzlehttp/guzzle 6.3.0 7.4.5 间接依赖 建议修复
guzzlehttp/psr7 1.4.2 2.4.5 间接依赖 建议修复
doctrine/orm v2.5.13 2.8.4 间接依赖 可选修复
mongodb/mongodb 1.2.0 1.9.2 间接依赖 可选修复
symfony/symfony v3.4.36 6.2.6 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 135
Apache-2.0 7
BSD-3-Clause 8
LGPL-2.0 7
LGPL-2.1 2
BSD-4-Clause 2
BSD-2-Clause 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
friendsofsymfony/message-bundle v1.3.0 间接依赖 composer
guzzlehttp/psr7 1.4.2 间接依赖 composer
symfony/config 间接依赖 composer
jms/metadata 1.6.0 间接依赖 composer
doctrine/inflector v1.2.0 间接依赖 composer
tubalmartin/cssmin v4.1.0 间接依赖 composer
hwi/oauth-bundle 0.5.3 间接依赖 composer
doctrine/mongodb-odm-bundle 3.4.1 间接依赖 composer
symfony/options-resolver 间接依赖 composer
symfony/polyfill-php70 v1.6.0 间接依赖 composer
symfony/polyfill-mbstring v1.6.0 间接依赖 composer
sensiolabs/security-checker v4.1.6 间接依赖 composer
php-http/httplug v1.1.0 间接依赖 composer
kriswallsmith/assetic v1.4.0 间接依赖 composer
jdorn/sql-formatter v1.2.17 间接依赖 composer
jms/i18n-routing-bundle 2.0.4 间接依赖 composer
mrclay/props-dic 2.2.0 间接依赖 composer
sonata-project/intl-bundle 2.4.0 间接依赖 composer
sonata-project/core-bundle 3.7.1 间接依赖 composer
symfony/templating 间接依赖 composer
sonata-project/exporter 1.8.0 间接依赖 composer
psr/http-message-implementation 间接依赖 composer
stof/doctrine-extensions-bundle v1.2.2 间接依赖 composer
ocramius/proxy-manager 2.1.1 间接依赖 composer
php-http/guzzle6-adapter v1.1.1 间接依赖 composer
willdurand/geocoder 4.1.0 间接依赖 composer
symfony/polyfill-apcu v1.6.0 间接依赖 composer
composer-plugin-api 间接依赖 composer
sonata-project/cache 2.0.1 间接依赖 composer
patchwork/jsqueeze v2.0.5 间接依赖 composer
symfony/polyfill-ctype v1.11.0 间接依赖 composer
symfony/monolog-bundle v3.1.2 间接依赖 composer
symfony/polyfill-php56 v1.6.0 间接依赖 composer
oneup/uploader-bundle 1.9.4 间接依赖 composer
symfony/security-core 间接依赖 composer
doctrine/data-fixtures v1.3.0 间接依赖 composer
willdurand/geocoder-bundle 5.1.0 间接依赖 composer
symfony/http-foundation 间接依赖 composer
friendsofsymfony/user-bundle v2.0.2 间接依赖 composer
doctrine/lexer v1.0.1 间接依赖 composer
symfony/polyfill-intl-icu v1.6.0 间接依赖 composer
mongodb/mongodb 1.2.0 间接依赖 composer
gedmo/doctrine-extensions v2.4.31 间接依赖 composer
php-http/client-implementation 间接依赖 composer
doctrine/annotations v1.6.0 间接依赖 composer
friendsofsymfony/ckeditor-bundle 2.1.0 间接依赖 composer
psr/container 1.0.0 间接依赖 composer
symfony/assetic-bundle v2.8.2 间接依赖 composer
knplabs/knp-menu 2.3.0 间接依赖 composer
doctrine/orm v2.5.13 间接依赖 composer
symfony/framework-bundle 间接依赖 composer
sonata-project/easy-extends-bundle 2.3.0 间接依赖 composer
guzzlehttp/guzzle 6.3.0 间接依赖 composer
container-interop/container-interop 1.2.0 间接依赖 composer
sonata-project/user-bundle 4.x-dev 间接依赖 composer
symfony/form 间接依赖 composer
egulias/email-validator 2.1.3 间接依赖 composer
php-http/message-factory v1.0.2 间接依赖 composer
geocoder-php/plugin 1.0.0 间接依赖 composer
knplabs/knp-menu-bundle v2.2.0 间接依赖 composer
whiteoctober/breadcrumbs-bundle 1.2.3 间接依赖 composer
components/jqueryui 1.12.1 间接依赖 composer
monolog/monolog 1.23.0 间接依赖 composer
doctrine/collections v1.5.0 间接依赖 composer
paragonie/random_compat v2.0.11 间接依赖 composer
symfony/routing 间接依赖 composer
symfony/validator 间接依赖 composer
robloach/component-installer 0.2.3 间接依赖 composer
ramsey/array_column 1.1.3 间接依赖 composer
sensio/framework-extra-bundle v5.1.3 间接依赖 composer
psr/link 1.0.0 间接依赖 composer
pimple/pimple v3.2.2 间接依赖 composer
doctrine/migrations v1.6.2 间接依赖 composer
clue/stream-filter v1.4.0 间接依赖 composer
symfony/http-kernel 间接依赖 composer
components/jquery 3.2.1 间接依赖 composer
symfony/dependency-injection 间接依赖 composer
doctrine/doctrine-bundle 1.8.1 间接依赖 composer
sonata-project/doctrine-orm-admin-bundle 3.2.0 间接依赖 composer
symfony/intl 间接依赖 composer
kriswallsmith/buzz v0.15.2 间接依赖 composer
alcaeus/mongo-php-adapter 1.1.3 间接依赖 composer
sonata-project/datagrid-bundle 2.3.1 间接依赖 composer
helios-ag/fm-elfinder-php-connector 2.5.7 间接依赖 composer
ocramius/package-versions 1.2.0 间接依赖 composer
behat/transliterator v1.2.0 间接依赖 composer
mrclay/jsmin-php 2.3.2 间接依赖 composer
doctrine/common v2.8.1 间接依赖 composer
guzzlehttp/promises v1.3.1 间接依赖 composer
symfony/twig-bundle 间接依赖 composer
symfony/asset 间接依赖 composer
doctrine/mongodb 1.6.1 间接依赖 composer
symfony/process 间接依赖 composer
incenteev/composer-parameter-handler v2.1.2 间接依赖 composer
psr/cache 1.0.1 间接依赖 composer
symfony/class-loader 间接依赖 composer
zendframework/zend-code 3.3.0 间接依赖 composer
symfony/security 间接依赖 composer
mrclay/minify 3.0.3 间接依赖 composer
doctrine/doctrine-cache-bundle 1.3.2 间接依赖 composer
psr/simple-cache 1.0.0 间接依赖 composer
symfony/console 间接依赖 composer
doctrine/doctrine-migrations-bundle v1.3.1 间接依赖 composer
symfony/twig-bridge 间接依赖 composer
symfony/security-acl v3.0.0 间接依赖 composer
symfony/monolog-bridge 间接依赖 composer
symfony/yaml 间接依赖 composer
psr/http-message 1.0.1 间接依赖 composer
helios-ag/fm-elfinder-bundle 6.2.1 间接依赖 composer
jms/di-extra-bundle 1.9.0 间接依赖 composer
sonata-project/block-bundle 3.9.0 间接依赖 composer
doctrine/instantiator 1.1.0 间接依赖 composer
doctrine/cache v1.7.1 间接依赖 composer
imagine/imagine v0.6.3 间接依赖 composer
nikic/php-parser v3.1.2 间接依赖 composer
geocoder-php/common-http 4.0.0 间接依赖 composer
symfony/filesystem 间接依赖 composer
simplethings/entity-audit-bundle v1.0.6 间接依赖 composer
twig/twig v2.12.3 间接依赖 composer
symfony/security-bundle 间接依赖 composer
jms/translation-bundle 1.3.2 间接依赖 composer
jms/aop-bundle 1.2.0 间接依赖 composer
symfony/swiftmailer-bundle v3.1.6 间接依赖 composer
lexik/currency-bundle v2.1.0 间接依赖 composer
symfony/symfony v3.4.36 间接依赖 composer
symfony/doctrine-bridge 间接依赖 composer
doctrine/doctrine-fixtures-bundle 3.0.2 间接依赖 composer
intervention/image 2.4.1 间接依赖 composer
sonata-project/admin-bundle 3.28.0 间接依赖 composer
jms/cg 1.2.0 间接依赖 composer
php-http/message 1.6.0 间接依赖 composer
symfony/polyfill-util v1.6.0 间接依赖 composer
sonata-project/doctrine-extensions 1.0.2 间接依赖 composer
symfony/expression-language 间接依赖 composer
intervention/httpauth 2.0.3 间接依赖 composer
twig/extensions v1.5.1 间接依赖 composer
php-http/discovery 1.3.0 间接依赖 composer
fig/link-util 1.0.0 间接依赖 composer
sensio/distribution-bundle v5.0.21 间接依赖 composer
a2lix/translation-form-bundle 2.1.2 间接依赖 composer
knplabs/doctrine-behaviors 1.5.0 间接依赖 composer
php-http/promise v1.0.0 间接依赖 composer
doctrine/mongodb-odm 1.2.1 间接依赖 composer
composer/ca-bundle 1.1.0 间接依赖 composer
cocur/slugify v3.0.1 间接依赖 composer
symfony/finder 间接依赖 composer
components/elfinder 2.2 间接依赖 composer
swiftmailer/swiftmailer v6.0.2 间接依赖 composer
symfony/property-access 间接依赖 composer
symfony/translation 间接依赖 composer
geocoder-php/google-maps-provider 4.1.0 间接依赖 composer
liip/imagine-bundle 1.9.1 间接依赖 composer
psr/log 1.0.2 间接依赖 composer
doctrine/dbal v2.6.3 间接依赖 composer
(0)
上一篇 2023年10月24日
下一篇 2023年10月24日

相关推荐

  • Chris2018998/BeeCP-Starter 软件分析报告

    基础信息 项目名称:Chris2018998/BeeCP-Starter 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716655082513940480/1716655083101143040 此报告由Mur…

    软件分析 2023年10月24日
    0
  • gaoyoubo/hexo-client 软件分析报告

    基础信息 项目名称:gaoyoubo/hexo-client 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718030065333829632/1718030065459658752 此报告由Murphysec…

    软件分析 2023年10月28日
    0
  • augustjoki/CubeTabBarController 软件分析报告

    基础信息 项目名称:augustjoki/CubeTabBarController 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716112474830061568/1716112478009344000 此报…

    软件分析 2023年10月23日
    0
  • dugwood/clickheat 软件分析报告

    基础信息 项目名称:dugwood/clickheat 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1717339168099139584/1717339168908640256 此报告由Murphysec提供 …

    软件分析 2023年10月26日
    0
  • gillescastel/inkscape-figures 软件分析报告

    基础信息 项目名称:gillescastel/inkscape-figures 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718117266334990336/1718117266406293504 此报告由…

    软件分析 2023年10月28日
    0