composer/packagist 软件分析报告

基础信息

项目名称:composer/packagist

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1716812244906016768/1716812245560328192

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Bootstrap 跨站脚本漏洞 XSS MPS-2018-9640 CVE-2018-14040 中危
Bootstrap 跨站脚本漏洞 XSS MPS-2018-9642 CVE-2018-14042 中危
Bootstrap跨站脚本漏洞 XSS MPS-2019-0181 CVE-2018-20676 中危
Bootstrap跨站脚本漏洞 XSS MPS-2019-0182 CVE-2018-20677 中危
Bootstrap 跨站脚本漏洞 XSS MPS-2019-0183 CVE-2016-10735 中危
Bootstrap 存在跨站脚本漏洞 XSS MPS-2019-1791 CVE-2019-8331 中危
algoliasearch-helper 安全漏洞 动态确定对象属性修改的控制不恰当 MPS-2021-19473 CVE-2021-23433 严重
instantsearch.js 存在跨站脚本漏洞 XSS MPS-2022-13787 中危
node-semver 安全漏洞 ReDoS MPS-2022-5166 CVE-2022-25883 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
bootstrap 3.3.5 4.3.1 直接依赖 建议修复
algoliasearch-helper 2.28.1 3.6.2 间接依赖 建议修复
instantsearch.js 2.10.5 4.3.1 直接依赖 可选修复
semver 5.7.1 7.5.2 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 220
BSD-3-Clause 15
ISC 15
BSD-2-Clause 2
LGPL-2.0 4
BSD-4-Clause 1
CC0-1.0 1
Apache-2.0 3
LGPL-3.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
snc/redis-bundle dev-custom_commands_config 间接依赖 composer
symfony/mailer v6.3.5 间接依赖 composer
agentkeepalive 2.2.0 间接依赖 npm
composer/ca-bundle 1.3.7 间接依赖 composer
phpdocumentor/reflection-common 2.2.0 间接依赖 composer
global 4.4.0 间接依赖 npm
normalize-path 3.0.0 间接依赖 npm
preact 8.5.3 间接依赖 npm
symfony/string v6.3.5 间接依赖 composer
twig/extra-bundle v3.7.1 间接依赖 composer
justinrainbow/json-schema v5.2.13 间接依赖 composer
league/oauth2-github 3.1.0 间接依赖 composer
ua-parser/uap-php v3.9.14 间接依赖 composer
symfony/deprecation-contracts v3.3.0 间接依赖 composer
egulias/email-validator 4.0.2 间接依赖 composer
react 17.0.2 直接依赖 npm
envify 4.1.0 间接依赖 npm
symfony/error-handler v6.3.5 间接依赖 composer
esbuild-freebsd-arm64 0.15.6 间接依赖 npm
knpuniversity/oauth2-client-bundle v2.15.0 间接依赖 composer
symfony/polyfill-php73 间接依赖 composer
symfony/polyfill-php83 v1.28.0 间接依赖 composer
is-binary-path 2.1.0 间接依赖 npm
symfony/security-csrf v6.3.2 间接依赖 composer
anymatch 3.1.2 间接依赖 npm
to-regex-range 5.0.1 间接依赖 npm
css-tree 1.1.3 间接依赖 npm
symfony/filesystem v6.3.1 间接依赖 composer
preact-render-to-string 3.8.2 间接依赖 npm
laminas/laminas-escaper 2.13.0 间接依赖 composer
composer/class-map-generator 1.1.0 间接依赖 composer
es6-promise 4.2.8 间接依赖 npm
esbuild-linux-riscv64 0.15.6 间接依赖 npm
enlightn/security-checker v1.10.0 间接依赖 composer
symfony/polyfill-uuid v1.28.0 间接依赖 composer
seld/phar-utils 1.2.1 间接依赖 composer
call-bind 1.0.2 间接依赖 npm
symfony/http-client-contracts v3.3.0 间接依赖 composer
js-tokens 4.0.0 间接依赖 npm
phpdocumentor/reflection-docblock 5.3.0 间接依赖 composer
scheb/2fa-backup-code v6.9.0 间接依赖 composer
psr/container 2.0.2 间接依赖 composer
doctrine/lexer 2.1.0 间接依赖 composer
readdirp 3.6.0 间接依赖 npm
esbuild-plugin-sass 1.0.1 直接依赖 npm
psr/log 3.0.0 间接依赖 composer
symfony/cache-contracts v3.3.0 间接依赖 composer
chokidar 3.5.3 间接依赖 npm
esbuild-android-64 0.15.6 间接依赖 npm
symfony/security-http v6.3.6 间接依赖 composer
esbuild-linux-mips64le 0.15.6 间接依赖 npm
symfony/event-dispatcher-contracts v3.3.0 间接依赖 composer
esbuild 0.15.6 直接依赖 npm
esbuild-windows-32 0.15.6 间接依赖 npm
symfony/twig-bridge v6.3.5 间接依赖 composer
symfony/routing v6.3.5 间接依赖 composer
paragonie/constant_time_encoding v2.6.3 间接依赖 composer
symfony/http-foundation v6.3.6 间接依赖 composer
symfony/validator v6.3.6 间接依赖 composer
twig/string-extra v3.7.1 间接依赖 composer
minimatch 3.1.2 间接依赖 npm
symfony/dependency-injection v6.3.5 间接依赖 composer
laminas/laminas-stdlib 3.18.0 间接依赖 composer
d3 3.5.17 直接依赖 npm
abbrev 1.1.1 间接依赖 npm
doctrine/sql-formatter 1.1.3 间接依赖 composer
psr/event-dispatcher 1.0.0 间接依赖 composer
knplabs/knp-menu-bundle v3.2.0 间接依赖 composer
composer/semver 3.4.0 间接依赖 composer
webmozart/assert 1.11.0 间接依赖 composer
symfony/options-resolver v6.3.0 间接依赖 composer
esbuild-openbsd-64 0.15.6 间接依赖 npm
symfony/polyfill-intl-idn v1.28.0 间接依赖 composer
symfony/lock v6.3.6 间接依赖 composer
psr/http-message 2.0 间接依赖 composer
glob 7.2.3 间接依赖 npm
composer/metadata-minifier 1.0.0 间接依赖 composer
composer-plugin-api 间接依赖 composer
predis/predis v2.2.2 间接依赖 composer
endroid/qr-code 5.0.2 间接依赖 composer
symfony/process v6.3.4 间接依赖 composer
esprima 4.0.1 间接依赖 npm
glob-parent 5.1.2 间接依赖 npm
esbuild-linux-64 0.15.6 间接依赖 npm
fsevents 2.3.2 间接依赖 npm
symfony/monolog-bundle v3.8.0 间接依赖 composer
guzzlehttp/promises 2.0.1 间接依赖 composer
nopt 1.0.10 间接依赖 npm
symfony/asset v6.3.0 间接依赖 composer
foreach 2.0.6 间接依赖 npm
side-channel 1.0.4 间接依赖 npm
symfony/property-info v6.3.0 间接依赖 composer
symfony/password-hasher v6.3.5 间接依赖 composer
min-document 2.19.0 间接依赖 npm
symfony/flex v2.4.0 间接依赖 composer
braces 3.0.2 间接依赖 npm
google/recaptcha 1.3.0 间接依赖 composer
symfony/mime v6.3.5 间接依赖 composer
psr/simple-cache 3.0.0 间接依赖 composer
doctrine/dbal 3.7.1 间接依赖 composer
react-is 16.13.1 间接依赖 npm
fill-range 7.0.1 间接依赖 npm
esbuild-windows-arm64 0.15.6 间接依赖 npm
composer/xdebug-handler 3.0.3 间接依赖 composer
lib-pcre 间接依赖 composer
immutability-helper 2.9.1 间接依赖 npm
to-factory 1.0.0 间接依赖 npm
twig/twig v3.7.1 间接依赖 composer
immutable 4.1.0 间接依赖 npm
mkdirp 0.3.0 间接依赖 npm
phpdocumentor/type-resolver 1.7.3 间接依赖 composer
symfony/polyfill-ctype 间接依赖 composer
isarray 2.0.5 间接依赖 npm
mdn-data 2.0.14 间接依赖 npm
laminas/laminas-diagnostics 1.24.0 间接依赖 composer
preact-context 1.1.4 间接依赖 npm
has 1.0.3 间接依赖 npm
doctrine/persistence 3.2.0 间接依赖 composer
object-assign 4.1.1 间接依赖 npm
cebe/markdown 1.2.1 间接依赖 composer
symfony/doctrine-bridge v6.3.6 间接依赖 composer
preact-rheostat 2.1.1 间接依赖 npm
symfonycasts/verify-email-bundle v1.14.0 间接依赖 composer
symfony/polyfill-mbstring v1.28.0 间接依赖 composer
querystring-es3 0.2.1 间接依赖 npm
source-map 0.6.1 间接依赖 npm
is-extglob 2.1.1 间接依赖 npm
tunnel-agent 0.6.0 间接依赖 npm
psr/cache 3.0.0 间接依赖 composer
symfony/runtime v6.3.2 间接依赖 composer
doctrine/event-manager 2.0.0 间接依赖 composer
invariant 2.2.4 间接依赖 npm
is-glob 4.0.3 间接依赖 npm
esbuild-freebsd-64 0.15.6 间接依赖 npm
phpstan/phpdoc-parser 1.24.2 间接依赖 composer
sass 1.47.0 间接依赖 npm
symfony/polyfill-intl-grapheme v1.28.0 间接依赖 composer
pagerfanta/core v4.2.0 间接依赖 composer
symfony/polyfill-intl-icu v1.28.0 间接依赖 composer
symfony/yaml v6.3.3 间接依赖 composer
has-symbols 1.0.3 间接依赖 npm
object-inspect 1.12.2 间接依赖 npm
ms 2.0.0 间接依赖 npm
react/promise v3.0.0 间接依赖 composer
guzzlehttp/psr7 2.6.1 间接依赖 composer
doctrine/orm 2.16.2 间接依赖 composer
esbuild-darwin-64 0.15.6 间接依赖 npm
graceful-fs 4.2.10 间接依赖 npm
composer/pcre 3.1.1 间接依赖 composer
symfony/service-contracts v3.3.0 间接依赖 composer
algoliasearch-helper 2.28.1 间接依赖 npm
fs-extra 10.0.0 间接依赖 npm
binary-extensions 2.2.0 间接依赖 npm
fs.realpath 1.0.0 间接依赖 npm
graze/dog-statsd 1.0.0 间接依赖 composer
esbuild-linux-s390x 0.15.6 间接依赖 npm
doctrine/doctrine-bundle 2.10.2 间接依赖 composer
psr/clock 1.0.0 间接依赖 composer
reduce 1.0.2 间接依赖 npm
function-bind 1.1.1 间接依赖 npm
seld/jsonlint 1.10.0 间接依赖 composer
spomky-labs/otphp 11.2.0 间接依赖 composer
qs 6.11.0 间接依赖 npm
wrappy 1.0.2 间接依赖 npm
algolia/algoliasearch-client-php 3.4.1 间接依赖 composer
symfony/twig-bundle v6.3.0 间接依赖 composer
doctrine/instantiator 2.0.0 间接依赖 composer
object.assign 4.1.4 间接依赖 npm
tmp 0.2.1 间接依赖 npm
define-properties 1.1.4 间接依赖 npm
dasprid/enum 1.0.5 间接依赖 composer
esbuild-sunos-64 0.15.6 间接依赖 npm
through 2.3.8 间接依赖 npm
doctrine/cache 2.2.0 间接依赖 composer
symfony/translation v6.3.6 间接依赖 composer
symfony/proxy-manager-bridge v6.3.0 间接依赖 composer
scheb/2fa-bundle v6.9.0 间接依赖 composer
symfony/translation-contracts v3.3.0 间接依赖 composer
process 0.11.10 间接依赖 npm
rimraf 3.0.2 间接依赖 npm
symfony/clock v6.3.4 间接依赖 composer
zustand 3.7.2 直接依赖 npm
symfony/config v6.3.2 间接依赖 composer
composer/composer dev-main 间接依赖 composer
laminas/laminas-feed 2.22.0 间接依赖 composer
knplabs/knp-menu v3.4.0 间接依赖 composer
react-dom 17.0.2 直接依赖 npm
psr/http-client 1.0.3 间接依赖 composer
events 1.1.1 间接依赖 npm
guzzlehttp/guzzle 7.8.0 间接依赖 composer
symfony/security-core v6.3.5 间接依赖 composer
doctrine/deprecations 1.1.2 间接依赖 composer
scheb/2fa-totp v6.9.0 间接依赖 composer
esbuild-linux-ppc64le 0.15.6 间接依赖 npm
loose-envify 1.4.0 间接依赖 npm
doctrine/common 3.4.3 间接依赖 composer
beelab/recaptcha2-bundle v2.7.0 间接依赖 composer
brace-expansion 1.1.11 间接依赖 npm
preact-compat 3.19.0 间接依赖 npm
esbuild-netbsd-64 0.15.6 间接依赖 npm
doctrine/inflector 2.0.8 间接依赖 composer
esbuild-windows-64 0.15.6 间接依赖 npm
symfony/polyfill-php80 间接依赖 composer
pagerfanta/doctrine-orm-adapter v4.2.0 间接依赖 composer
hogan.js 3.0.2 间接依赖 npm
safe-buffer 5.2.1 间接依赖 npm
has-property-descriptors 1.0.0 间接依赖 npm
symfony/serializer v6.3.6 间接依赖 composer
get-intrinsic 1.1.2 间接依赖 npm
path-is-absolute 1.0.1 间接依赖 npm
nelmio/cors-bundle 2.3.1 间接依赖 composer
semver 5.7.1 间接依赖 npm
laminas/laminas-code 4.13.0 间接依赖 composer
symfony/event-dispatcher v6.3.2 间接依赖 composer
jsonfile 6.1.0 间接依赖 npm
inflight 1.0.6 间接依赖 npm
monolog/monolog 3.4.0 间接依赖 composer
picomatch 2.3.1 间接依赖 npm
inherits 2.0.4 间接依赖 npm
lcobucci/clock 3.0.0 间接依赖 composer
instantsearch.js 2.10.5 直接依赖 npm
symfony/finder v6.3.5 间接依赖 composer
esbuild-linux-32 0.15.6 间接依赖 npm
esbuild-linux-arm 0.15.6 间接依赖 npm
symfony/http-client v6.3.6 间接依赖 composer
object-keys 1.1.1 间接依赖 npm
symfony/monolog-bridge v6.3.1 间接依赖 composer
scheduler 0.20.2 间接依赖 npm
symfony/polyfill-php81 间接依赖 composer
symfony/polyfill-php72 间接依赖 composer
symfony/intl v6.3.2 间接依赖 composer
symfony/cache v6.3.6 间接依赖 composer
seld/signal-handler 2.0.2 间接依赖 composer
esbuild-darwin-arm64 0.15.6 间接依赖 npm
plausible-tracker 0.3.8 直接依赖 npm
@esbuild/linux-loong64 0.15.6 间接依赖 npm
scheb/2fa-trusted-device v6.9.0 间接依赖 composer
classnames 2.3.1 间接依赖 npm
standalone-react-addons-pure-render-mixin 0.1.1 间接依赖 npm
algoliasearch 3.35.1 间接依赖 npm
league/oauth2-client 2.7.0 间接依赖 composer
pretty-format 3.8.0 间接依赖 npm
symfony/polyfill-intl-normalizer v1.28.0 间接依赖 composer
prop-types 15.8.1 间接依赖 npm
symfony/dotenv v6.3.0 间接依赖 composer
paragonie/random_compat 间接依赖 composer
babdev/pagerfanta-bundle v4.2.1 间接依赖 composer
bacon/bacon-qr-code 2.0.8 间接依赖 composer
bootstrap 3.3.5 直接依赖 npm
esbuild-android-arm64 0.15.6 间接依赖 npm
symfony/property-access v6.3.2 间接依赖 composer
ezyang/htmlpurifier v4.16.0 间接依赖 composer
composer-runtime-api 间接依赖 composer
symfony/var-exporter v6.3.6 间接依赖 composer
symfony/var-dumper v6.3.6 间接依赖 composer
symfony/http-kernel v6.3.6 间接依赖 composer
jquery 3.6.1 直接依赖 npm
symfony/security-bundle v6.3.6 间接依赖 composer
esbuild-linux-arm64 0.15.6 间接依赖 npm
debug 2.6.9 间接依赖 npm
composer/spdx-licenses 1.5.7 间接依赖 composer
pagerfanta/twig v4.2.0 间接依赖 composer
nvd3 1.8.6 直接依赖 npm
symfony/web-link v6.3.0 间接依赖 composer
symfony/expression-language v6.3.0 间接依赖 composer
nelmio/security-bundle v3.0.0 间接依赖 composer
symfony/uid v6.3.0 间接依赖 composer
symfony/framework-bundle v6.3.6 间接依赖 composer
friendsofphp/proxy-manager-lts v1.0.16 间接依赖 composer
doctrine/annotations 2.0.1 间接依赖 composer
lodash 4.17.21 间接依赖 npm
preact-transition-group 1.1.1 间接依赖 npm
psr/link 2.0.1 间接依赖 composer
doctrine/collections 2.1.4 间接依赖 composer
universalify 2.0.0 间接依赖 npm
lcobucci/jwt 5.0.0 间接依赖 composer
dom-walk 0.1.2 间接依赖 npm
symfony/console v6.3.4 间接依赖 composer
symfony/form v6.3.6 间接依赖 composer
source-map-js 1.0.2 间接依赖 npm
load-script 1.0.0 间接依赖 npm
once 1.4.0 间接依赖 npm
(0)
上一篇 2023年10月24日
下一篇 2023年10月24日

相关推荐

  • howtomakeaturn/Outlaw 软件分析报告

    基础信息 项目名称:howtomakeaturn/Outlaw 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718666789789499392/1718666789835636736 此报告由Murphyse…

    软件分析 2023年10月30日
    0
  • artf/grapesjs 软件分析报告

    基础信息 项目名称:artf/grapesjs 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716049324378210304/1716049324634062848 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年10月23日
    0
  • GoogleContainerTools/kaniko 软件分析报告

    基础信息 项目名称:GoogleContainerTools/kaniko 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718303538522226688/1718303538622889984 此报告由Mu…

    软件分析 2023年10月29日
    0
  • awslabs/amazon-kinesis-client-python 软件分析报告

    基础信息 项目名称:awslabs/amazon-kinesis-client-python 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1731566393692217344/17315663940235673…

    软件分析 2023年12月4日
    0
  • defunct/manifold 软件分析报告

    基础信息 项目名称:defunct/manifold 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721130197780004864/1722657810309287936 此报告由Murphysec提供 漏…

    软件分析 2023年11月10日
    0