基础信息
项目名称:danfickle/openhtmltopdf
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717021995182112768/1717021996226494464
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Apache Commons IO 存在路径遍历漏洞 | 路径遍历 | MPS-2021-4531 | CVE-2021-29425 | 中危 |
org.mozilla:rhino | XXE | MPS-2022-11928 | 高危 | |
com.beust:jcommander 存在从非可信控制范围包含功能例程漏洞 | 从非可信控制范围包含功能例程 | MPS-2022-12225 | 中危 | |
org.freemarker:freemarker | 代码注入 | MPS-2022-12438 | 高危 | |
Apache Xalan 存在整数截断漏洞 | 数值截断错误 | MPS-2022-19461 | CVE-2022-34169 | 中危 |
snakeYAML | 拒绝服务 | MPS-2022-5144 | CVE-2022-25857 | 高危 |
jsoup | XSS | MPS-2022-51547 | CVE-2022-36033 | 中危 |
Apache Batik 信息泄露漏洞 | 未授权敏感信息泄露 | MPS-2022-55649 | CVE-2022-38398 | 中危 |
Apache Batik 存在 SSRF 漏洞 | 未授权敏感信息泄露 | MPS-2022-55890 | CVE-2022-38648 | 中危 |
snakeYAML | 栈缓冲区溢出 | MPS-2022-56040 | CVE-2022-38751 | 中危 |
snakeYAML | 栈缓冲区溢出 | MPS-2022-56041 | CVE-2022-38752 | 低危 |
snakeYAML | 栈缓冲区溢出 | MPS-2022-56051 | CVE-2022-38750 | 中危 |
snakeYAML | 拒绝服务 | MPS-2022-56081 | CVE-2022-38749 | 中危 |
Apache Batik DefaultScriptSecurity 函数存在 SSRF 漏洞 | 未授权敏感信息泄露 | MPS-2022-57733 | CVE-2022-40146 | 中危 |
SnakeYAML | 栈缓冲区溢出 | MPS-2022-58478 | CVE-2022-41854 | 中危 |
Apache Batik visibleToScripts 信息泄露漏洞 | 未授权敏感信息泄露 | MPS-2022-59716 | CVE-2022-42890 | 中危 |
Apache XML Graphics Batik | SSRF | MPS-2022-63578 | CVE-2022-44729 | 中危 |
Apache XML Graphics Batik 代码问题漏洞 | SSRF | MPS-2022-63579 | CVE-2022-44730 | 中危 |
snakeYAML | 反序列化 | MPS-2022-9425 | CVE-2022-1471 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
org.apache.xmlgraphics:batik-transcoder | 1.14 | 1.17 | 直接依赖 | 强烈建议修复 |
org.apache.xmlgraphics:batik-bridge | 1.14 | 1.17 | 间接依赖 | 强烈建议修复 |
org.mozilla:rhino | 1.7.11 | 1.7.12 | 间接依赖 | 建议修复 |
org.yaml:snakeyaml | 1.26 | 2.0 | 直接依赖 | 建议修复 |
org.freemarker:freemarker | 2.3.27-incubating | 2.3.30 | 直接依赖 | 建议修复 |
xalan:xalan | 2.7.2 | 间接依赖 | 建议修复 | |
commons-io:commons-io | 2.4 | 2.7 | 间接依赖 | 可选修复 |
org.jsoup:jsoup | 1.14.2 | 1.15.3 | 直接依赖 | 可选修复 |
com.beust:jcommander | 1.72 | 1.75 | 间接依赖 | 可选修复 |
commons-io:commons-io | 1.3.1 | 2.7 | 间接依赖 | 可选修复 |
org.apache.xmlgraphics:batik-script | 1.14 | 1.17 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 49 | 低 |
自定义许可证 | 12 | 低 |
LGPL-2.1-or-later | 8 | 低 |
MPL-2.0 | 2 | 低 |
MIT | 4 | 低 |
LGPL-2.1 | 1 | 中 |
MPL-1.1 | 1 | 低 |
GPL-3.0 | 6 | 中 |
CDDL-1.1 | 1 | 低 |
BSD-3-Clause | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
org.apache.xmlgraphics:batik-css | 1.9 | 间接依赖 | maven |
com.sun.xml.bind:jaxb-core | 2.3.0.1 | 间接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-mathml-support | 1.0.11-SNAPSHOT | 直接依赖 | maven |
org.apache.xmlgraphics:batik-awt-util | 1.14 | 间接依赖 | maven |
MSVCRT.dll | 间接依赖 | ||
org.apache.xmlgraphics:xmlgraphics-commons | 2.6 | 直接依赖 | maven |
ole32.dll | 间接依赖 | ||
org.mozilla:rhino | 1.7.11 | 间接依赖 | maven |
KERNEL32.dll | 间接依赖 | ||
org.apache.xmlgraphics:batik-css | 1.14 | 间接依赖 | maven |
commons-logging:commons-logging | 1.0.4 | 间接依赖 | maven |
xalan:serializer | 2.7.2 | 间接依赖 | maven |
javax.activation:javax.activation-api | 1.2.0 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-anim | 1.14 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-constants | 1.14 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-gvt | 1.14 | 间接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-latex-support | 1.0.11-SNAPSHOT | 直接依赖 | maven |
org.apache.xmlgraphics:batik-i18n | 1.14 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-xml | 1.14 | 间接依赖 | maven |
org.apache.commons:commons-math3 | 3.2 | 间接依赖 | maven |
commons-logging:commons-logging | 1.2 | 间接依赖 | maven |
xml-apis:xml-apis | 1.3.04 | 间接依赖 | maven |
org.slf4j:slf4j-simple | 1.7.30 | 直接依赖 | maven |
plc4.dll | 间接依赖 | ||
org.yaml:snakeyaml | 1.26 | 直接依赖 | maven |
com.google.zxing:javase | 3.4.0 | 直接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-objects | 1.0.11-SNAPSHOT | 直接依赖 | maven |
net.java.dev.stax-utils:stax-utils | 20070216 | 间接依赖 | maven |
urlmon.dll | 间接依赖 | ||
SHLWAPI.dll | 间接依赖 | ||
org.freemarker:freemarker | 2.3.27-incubating | 直接依赖 | maven |
org.openjdk.jmh:jmh-core | 1.25.2 | 直接依赖 | maven |
org.javassist:javassist | 3.20.0-GA | 间接依赖 | maven |
org.verapdf:metadata-fixer | 1.18.8 | 间接依赖 | maven |
org.verapdf:feature-reporting | 1.18.8 | 间接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-rtl-support | 1.0.11-SNAPSHOT | 直接依赖 | maven |
org.apache.xmlgraphics:batik-bridge | 1.14 | 间接依赖 | maven |
org.apache.pdfbox:fontbox | 2.0.25 | 间接依赖 | maven |
com.sun.xml.bind:jaxb-impl | 2.3.2 | 间接依赖 | maven |
org.openjdk.jmh:jmh-generator-annprocess | 1.25.2 | 直接依赖 | maven |
com.ibm.icu:icu4j | 59.1 | 直接依赖 | maven |
de.rototor.snuggletex:snuggletex-core | 1.3.0 | 直接依赖 | maven |
org.apache.xmlgraphics:batik-svggen | 1.14 | 间接依赖 | maven |
ognl:ognl | 3.1.12 | 间接依赖 | maven |
SHELL32.dll | 间接依赖 | ||
org.slf4j:slf4j-api | 1.7.25 | 间接依赖 | maven |
WINSPOOL.DRV | 间接依赖 | ||
de.rototor.pdfbox:graphics2d | 0.34 | 直接依赖 | maven |
commons-io:commons-io | 1.3.1 | 间接依赖 | maven |
nspr4.dll | 间接依赖 | ||
GDI32.dll | 间接依赖 | ||
org.apache.xmlgraphics:batik-codec | 1.14 | 直接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-core | 1.0.11-SNAPSHOT | 直接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-pdfbox | 1.0.11-SNAPSHOT | 直接依赖 | maven |
javax.xml.bind:jaxb-api | 2.4.0-b180830.0359 | 间接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-java2d | 1.0.11-SNAPSHOT | 直接依赖 | maven |
ADVAPI32.dll | 间接依赖 | ||
org.thymeleaf:thymeleaf | 3.0.11.RELEASE | 直接依赖 | maven |
org.apache.xmlgraphics:batik-ext | 1.14 | 直接依赖 | maven |
org.apache.xmlgraphics:batik-dom | 1.14 | 间接依赖 | maven |
net.sf.jopt-simple:jopt-simple | 4.6 | 间接依赖 | maven |
org.mozilla:rhino | 1.7.13 | 直接依赖 | maven |
org.jfree:jfreechart | 1.5.0 | 直接依赖 | maven |
xalan:xalan | 2.7.2 | 间接依赖 | maven |
xml-apis:xml-apis-ext | 1.3.04 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-script | 1.14 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-svg-dom | 1.14 | 间接依赖 | maven |
org.verapdf:parser | 1.18.2 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-transcoder | 1.14 | 直接依赖 | maven |
de.rototor.jeuclid:jeuclid-core | 3.1.12 | 直接依赖 | maven |
commons-logging:commons-logging | 1.1.1 | 间接依赖 | maven |
org.apache.pdfbox:xmpbox | 2.0.25 | 直接依赖 | maven |
org.apache.xmlgraphics:batik-parser | 1.9 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-shared-resources | 1.14 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-parser | 1.14 | 间接依赖 | maven |
com.openhtmltopdf:openhtmltopdf-svg-support | 1.0.11-SNAPSHOT | 直接依赖 | maven |
USER32.dll | 间接依赖 | ||
com.google.zxing:core | 3.4.0 | 间接依赖 | maven |
org.jsoup:jsoup | 1.14.2 | 直接依赖 | maven |
org.apache.xmlgraphics:batik-util | 1.14 | 间接依赖 | maven |
com.beust:jcommander | 1.72 | 间接依赖 | maven |
xml-apis:xml-apis | 1.4.01 | 间接依赖 | maven |
org.unbescape:unbescape | 1.1.6.RELEASE | 间接依赖 | maven |
commons-io:commons-io | 2.4 | 间接依赖 | maven |
org.verapdf:core | 1.18.11 | 间接依赖 | maven |
org.imgscalr:imgscalr-lib | 4.2 | 直接依赖 | maven |
org.verapdf:validation-model | 1.18.8 | 直接依赖 | maven |
org.verapdf:pdf-model | 1.18.3 | 间接依赖 | maven |
org.apache.xmlgraphics:batik-svg-dom | 1.9 | 间接依赖 | maven |
com.github.jai-imageio:jai-imageio-core | 1.4.0 | 间接依赖 | maven |
org.verapdf:verapdf-xmp-core | 1.18.11 | 间接依赖 | maven |
org.attoparser:attoparser | 2.0.5.RELEASE | 间接依赖 | maven |
org.codelibs:jhighlight | 1.0.3 | 直接依赖 | maven |
org.thymeleaf.extras:thymeleaf-extras-java8time | 3.0.4.RELEASE | 直接依赖 | maven |
org.apache.pdfbox:pdfbox | 2.0.25 | 直接依赖 | maven |