cycloidio/terracognita 软件分析报告

基础信息

项目名称:cycloidio/terracognita

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1716997973266448384/1716997973400666112

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
低危
HashiCorp go-getter 输入验证错误漏洞 命令注入 MPS-2022-10131 CVE-2022-30321 高危
HashiCorp go-getter 输入验证错误漏洞 权限、特权和访问控制 MPS-2022-10132 CVE-2022-30322 高危
HashiCorp go-getter 输入验证错误漏洞 权限、特权和访问控制 MPS-2022-10133 CVE-2022-30323 高危
HashiCorp go-getter 命令注入漏洞 命令注入 MPS-2022-6321 CVE-2022-26945 严重
HashiCorp go-getter 安全漏洞 拒绝服务 MPS-2023-2834 CVE-2023-0475 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
github.com/hashicorp/go-getter v1.5.11 1.7.0 间接依赖 强烈建议修复
golang.org/x/net v0.7.0 0.17.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 41
Apache-2.0 61
Unicode-DFS-2016 1
MPL-2.0 33
BSD-3-Clause 24
BSD-2-Clause 6
ISC 1
GPL-3.0 1
GPL-3.0-or-later 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/apparentlymart/go-textseg/v13 v13.0.0 间接依赖 go
github.com/hashicorp/terraform-plugin-go v0.10.0 直接依赖 go
github.com/klauspost/compress v1.13.1 间接依赖 go
github.com/envoyproxy/protoc-gen-validate v0.1.0 间接依赖 go
github.com/inconshreveable/mousetrap v1.0.0 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/Azure/go-autorest/autorest/date v0.3.0 间接依赖 go
github.com/hashicorp/go-plugin v1.4.4 间接依赖 go
golang.org/x/sys v0.5.0 间接依赖 go
github.com/gammazero/deque v0.0.0-20180920172122-f6adf94963e4 间接依赖 go
google.golang.org/grpc v1.47.0 直接依赖 go
github.com/xeipuuv/gojsonschema v1.2.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.7 间接依赖 go
github.com/aws/aws-sdk-go-v2/config v1.15.0 间接依赖 go
github.com/hashicorp/terraform-json v0.14.0 间接依赖 go
github.com/Azure/go-autorest/tracing v0.6.0 间接依赖 go
github.com/cncf/xds/go v0.0.0-20211011173535-cb28da3451f1 间接依赖 go
github.com/googleapis/gax-go/v2 v2.1.1 间接依赖 go
github.com/hashicorp/go-cty v1.4.1-0.20200414143053-d3edf31b6320 直接依赖 go
github.com/kylelemons/godebug v1.1.0 间接依赖 go
cloud.google.com/go v0.97.0 间接依赖 go
github.com/hashicorp/go-cleanhttp v0.5.2 间接依赖 go
github.com/hashicorp/terraform-plugin-log v0.4.1 间接依赖 go
github.com/Azure/go-autorest/autorest/adal v0.9.18 间接依赖 go
github.com/grpc-ecosystem/go-grpc-middleware v1.3.0 间接依赖 go
github.com/manicminer/hamilton v0.44.0 间接依赖 go
github.com/agext/levenshtein v1.2.3 间接依赖 go
google.golang.org/protobuf v1.28.0 间接依赖 go
github.com/aws/aws-sdk-go v1.43.34 直接依赖 go
github.com/stretchr/testify v1.7.2 直接依赖 go
github.com/vmihailenco/tagparser v0.1.1 间接依赖 go
github.com/hashicorp/go-uuid v1.0.3 间接依赖 go
golang.org/x/oauth2 v0.0.0-20211104180415-d3ed0bb246c8 间接依赖 go
github.com/aws/aws-sdk-go-v2 v1.16.2 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.9 间接依赖 go
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
github.com/spf13/jwalterweatherman v1.0.0 间接依赖 go
go.opencensus.io v0.23.0 间接依赖 go
github.com/Azure/go-autorest/autorest v0.11.27 直接依赖 go
github.com/hashicorp/go-checkpoint v0.5.0 间接依赖 go
github.com/vmihailenco/msgpack v4.0.4+incompatible 间接依赖 go
github.com/cespare/xxhash/v2 v2.1.1 间接依赖 go
github.com/hashicorp/go-hclog v1.2.1 间接依赖 go
github.com/dimchansky/utfbom v1.1.1 间接依赖 go
github.com/oklog/run v1.1.0 间接依赖 go
github.com/evanphx/json-patch v4.12.0+incompatible 间接依赖 go
github.com/mitchellh/go-wordwrap v1.0.1 间接依赖 go
github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.14 间接依赖 go
github.com/GoogleCloudPlatform/declarative-resource-client-library v0.0.0-20220114025148-a9879027a727 间接依赖 go
google.golang.org/api v0.61.0 直接依赖 go
github.com/spf13/viper v1.7.1 直接依赖 go
github.com/hashicorp/terraform-svchost v0.0.0-20200729002733-f050f53b9734 间接依赖 go
github.com/spf13/afero v1.2.2 间接依赖 go
github.com/hashicorp/aws-sdk-go-base/v2/awsv1shim/v2 v2.0.0-beta.15 间接依赖 go
github.com/mitchellh/copystructure v1.2.0 间接依赖 go
github.com/hashicorp/awspolicyequivalence v1.5.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/iam v1.18.0 间接依赖 go
github.com/Azure/go-autorest/autorest/validation v0.3.1 间接依赖 go
github.com/hashicorp/terraform-provider-aws v1.60.1-0.20210513231836-489654890359 直接依赖 go
cloud.google.com/go/bigtable v1.10.1 间接依赖 go
github.com/go-kit/kit v0.9.0 直接依赖 go
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
github.com/golang/mock v1.6.0 直接依赖 go
google.golang.org/genproto v0.0.0-20211118181313-81c1377c94b1 间接依赖 go
github.com/mattbaird/jsonpatch v0.0.0-20200820163806-098863c1fc24 间接依赖 go
github.com/golang-jwt/jwt/v4 v4.4.1 间接依赖 go
github.com/magiconair/properties v1.8.1 间接依赖 go
github.com/pelletier/go-toml v1.2.0 间接依赖 go
github.com/mitchellh/mapstructure v1.5.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.0 间接依赖 go
github.com/vmware/govmomi v0.28.0 直接依赖 go
github.com/btubbs/datetime v0.1.0 间接依赖 go
github.com/google/go-cmp v0.5.8 间接依赖 go
github.com/sirupsen/logrus v1.8.1 间接依赖 go
github.com/hashicorp/terraform-registry-address v0.0.0-20220623143253-7d51757b572c 间接依赖 go
github.com/golang/snappy v0.0.3 间接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.3 间接依赖 go
github.com/mattn/go-colorable v0.1.12 间接依赖 go
github.com/Azure/azure-sdk-for-go v65.0.0+incompatible 直接依赖 go
github.com/fatih/color v1.13.0 间接依赖 go
github.com/coreos/go-systemd v0.0.0-20190620071333-e64a0ec8b42a 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/sts v1.16.0 间接依赖 go
github.com/Azure/go-autorest v14.2.0+incompatible 间接依赖 go
github.com/cenkalti/backoff v2.2.1+incompatible 间接依赖 go
github.com/hashicorp/go-getter v1.5.11 间接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
github.com/aws/smithy-go v1.11.2 间接依赖 go
github.com/tombuildsstuff/giovanni v0.20.0 间接依赖 go
github.com/Azure/go-autorest/autorest/to v0.4.0 间接依赖 go
github.com/gofrs/uuid v4.0.0+incompatible 间接依赖 go
github.com/zclconf/go-cty v1.10.0 直接依赖 go
github.com/hashicorp/hcl/v2 v2.13.0 直接依赖 go
github.com/hashicorp/hcl v1.0.0 间接依赖 go
github.com/apparentlymart/go-versions v1.0.1 间接依赖 go
github.com/hashicorp/terraform-plugin-sdk/v2 v2.18.0 直接依赖 go
github.com/hashicorp/terraform v0.13.0 直接依赖 go
golang.org/x/net v0.7.0 间接依赖 go
github.com/cycloidio/mxwriter v1.0.4 直接依赖 go
github.com/go-logfmt/logfmt v0.4.0 间接依赖 go
github.com/hashicorp/logutils v1.0.0 间接依赖 go
github.com/hashicorp/terraform-provider-google v1.20.1-0.20210510171431-a764cf3da527 直接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
github.com/cycloidio/tfdocs v0.0.0-20230516095646-1dc8f8412d50 直接依赖 go
github.com/ulikunitz/xz v0.5.10 间接依赖 go
github.com/apparentlymart/go-cidr v1.1.0 间接依赖 go
github.com/hashicorp/go-azure-helpers v0.40.0 直接依赖 go
github.com/Azure/go-autorest/logger v0.2.1 间接依赖 go
github.com/chr4/pwgen v1.1.0 直接依赖 go
github.com/mitchellh/reflectwalk v1.0.2 间接依赖 go
github.com/xeipuuv/gojsonpointer v0.0.0-20180127040702-4e3ac2762d5f 间接依赖 go
github.com/hashicorp/go-version v1.6.0 间接依赖 go
github.com/census-instrumentation/opencensus-proto v0.2.1 间接依赖 go
github.com/rickb777/date v1.12.5-0.20200422084442-6300e543c4d9 间接依赖 go
github.com/manicminer/hamilton-autorest v0.2.0 间接依赖 go
golang.org/x/xerrors v0.0.0-20220609144429-65e65417b02f 间接依赖 go
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b 间接依赖 go
github.com/jinzhu/inflection v1.0.0 直接依赖 go
github.com/subosito/gotenv v1.2.0 间接依赖 go
github.com/mattn/go-isatty v0.0.14 间接依赖 go
github.com/fsnotify/fsnotify v1.4.9 间接依赖 go
github.com/gertd/go-pluralize v0.1.7 直接依赖 go
github.com/hashicorp/yamux v0.0.0-20210316155119-a95892c5f864 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/route53domains v1.12.3 间接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
github.com/spf13/pflag v1.0.5 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/sso v1.11.0 间接依赖 go
golang.org/x/crypto v0.0.0-20220517005047-85d78b3ac167 间接依赖 go
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d 间接依赖 go
github.com/hashicorp/go-retryablehttp v0.7.0 间接依赖 go
golang.org/x/text v0.7.0 直接依赖 go
github.com/vmihailenco/msgpack/v4 v4.3.12 间接依赖 go
github.com/beevik/etree v1.1.0 间接依赖 go
github.com/shopspring/decimal v1.3.1 间接依赖 go
github.com/adrg/xdg v0.2.3 直接依赖 go
github.com/spf13/cast v1.3.0 间接依赖 go
github.com/xeipuuv/gojsonreference v0.0.0-20180127040603-bd5ef7bd5415 间接依赖 go
github.com/mitchellh/hashstructure v1.1.0 间接依赖 go
github.com/hashicorp/go-safetemp v1.0.0 间接依赖 go
github.com/cncf/udpa/go v0.0.0-20210930031921-04548b0d99d4 间接依赖 go
github.com/pascaldekloe/name v1.0.1 直接依赖 go
github.com/aws/aws-sdk-go-v2/credentials v1.10.0 间接依赖 go
gopkg.in/yaml.v2 v2.4.0 直接依赖 go
github.com/coreos/pkg v0.0.0-20180928190104-399ea9e2e55f 间接依赖 go
github.com/hashicorp/terraform-exec v0.17.2 间接依赖 go
github.com/kr/logfmt v0.0.0-20140226030751-b84e30acd515 间接依赖 go
github.com/mitchellh/go-testing-interface v1.14.1 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.0 间接依赖 go
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4 间接依赖 go
github.com/envoyproxy/go-control-plane v0.10.2-0.20220325020618-49ff273808a1 间接依赖 go
github.com/spf13/cobra v1.1.3 直接依赖 go
cloud.google.com/go/storage v1.16.0 间接依赖 go
github.com/rickb777/plural v1.2.0 间接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
github.com/Azure/go-autorest/autorest/azure/cli v0.4.5 间接依赖 go
bitbucket.org/creachadair/stringset v0.0.8 间接依赖 go
github.com/hashicorp/aws-cloudformation-resource-schema-sdk-go v0.16.0 间接依赖 go
github.com/hashicorp/terraform-provider-vsphere v1.26.1-0.20220510172607-30f37d268d79 直接依赖 go
github.com/gammazero/workerpool v0.0.0-20181230203049-86a96b5d5d92 间接依赖 go
github.com/hashicorp/terraform-provider-azurerm v1.44.1-0.20201029183808-d721bcc1bb55 直接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/hashicorp/go-azure-sdk v0.20220824.1090858 间接依赖 go
github.com/hashicorp/hc-install v0.4.0 间接依赖 go
github.com/golang/protobuf v1.5.2 间接依赖 go
gopkg.in/ini.v1 v1.66.2 间接依赖 go
github.com/ProtonMail/go-crypto v0.0.0-20210428141323-04723f9f07d7 间接依赖 go
github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826 间接依赖 go
(0)
上一篇 2023年10月25日
下一篇 2023年10月25日

相关推荐

  • schollz/croc 软件分析报告

    基础信息 项目名称:schollz/croc 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1744046315100581888/1744046315452903424 此报告由Murphysec提供 漏洞列表 …

    软件分析 2024年1月8日
    0
  • jdrucey/esp8266-fastled-webserver 软件分析报告

    基础信息 项目名称:jdrucey/esp8266-fastled-webserver 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721299766297001984/1728426923694448640 …

    软件分析 2023年11月25日
    0
  • zyedidia/micro 软件分析报告

    基础信息 项目名称:zyedidia/micro 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1720433480695189504/1720433481114619904 此报告由Murphysec提供 漏洞列…

    软件分析 2023年11月3日
    0
  • hyperchain/hyperchain 软件分析报告

    基础信息 项目名称:hyperchain/hyperchain 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718731682839576576/1718731682898296832 此报告由Murphyse…

    软件分析 2023年10月30日
    0
  • ActiveJpa/activejpa 软件分析报告

    基础信息 项目名称:ActiveJpa/activejpa 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715513069420724224/1715513069596884992 此报告由Murphysec提…

    软件分析 2023年10月23日
    0