基础信息
项目名称:Dataherald/dataherald
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717057910881435648/1717057911082762240
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
httpx 存在输入验证不恰当漏洞 | 输入验证不恰当 | MPS-2022-14944 | 中危 | |
OpenSSL 安全漏洞 | 过度迭代 | MPS-n3pe-ljgc | CVE-2023-3817 | 中危 |
python-cryptography 信任管理问题漏洞 | 证书验证不恰当 | MPS-sj5m-20tf | CVE-2023-38325 | 高危 |
langchain注入漏洞 | 注入 | MPS-x9qb-uct8 | CVE-2023-39659 | 严重 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
cryptography | 40.0.2 | 41.0.3 | 间接依赖 | 建议修复 |
langchain | 0.0.312 | 间接依赖 | 可选修复 | |
httpx | 0.24.1 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 8 | 低 |
Apache-2.0 | 8 | 低 |
ISC | 1 | 低 |
自定义许可证 | 6 | 低 |
PSF-2.0 AND (Apache-2.0 OR BSD-3-Clause) | 1 | 低 |
BSD-3-Clause | 2 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
mypy-extensions | 1.0.0 | 间接依赖 | pip |
chromadb | 0.4.12 | 间接依赖 | pip |
overrides | 7.3.1 | 间接依赖 | pip |
langchain | 0.0.312 | 间接依赖 | pip |
dnspython | 2.3.0 | 间接依赖 | pip |
snowflake-connector-python | 3.0.4 | 间接依赖 | pip |
pytest-dotenv | 0.5.2 | 间接依赖 | pip |
sql-metadata | 2.8.0 | 间接依赖 | pip |
abstractmethod | 间接依赖 | pip | |
botocore | 1.31.38 | 间接依赖 | pip |
Tuple | 间接依赖 | pip | |
pymongo | 4.4.0 | 间接依赖 | pip |
bson | 间接依赖 | pip | |
databricks-sql-connector | 2.7.0 | 间接依赖 | pip |
psycopg2 | 2.9.6 | 间接依赖 | pip |
boto3 | 1.28.38 | 间接依赖 | pip |
/app/requirements.txt | 间接依赖 | pip | |
AlephAlpha | 间接依赖 | pip | |
Any | 间接依赖 | pip | |
Callable | 间接依赖 | pip | |
pinecone-client | 2.2.2 | 间接依赖 | pip |
PyAthena | 3.0.6 | 间接依赖 | pip |
fastapi | 0.98.0 | 间接依赖 | pip |
packaging | 23.1 | 间接依赖 | pip |
Dict | 间接依赖 | pip | |
ChatCohere | 间接依赖 | pip | |
pydantic | 1.10.9 | 间接依赖 | pip |
sshtunnel | 0.4.0 | 间接依赖 | pip |
sphinx | 6.2.1 | 间接依赖 | pip |
openapi-schema-pydantic | 1.2.4 | 间接依赖 | pip |
cryptography | 40.0.2 | 间接依赖 | pip |
requests | 2.31.0 | 间接依赖 | pip |
SQLAlchemy | 1.4.49 | 间接依赖 | pip |
sqlparse | 0.4.4 | 间接依赖 | pip |
sqlalchemy-bigquery | 1.6.1 | 间接依赖 | pip |
uvicorn | 0.22.0 | 间接依赖 | pip |
snowflake-sqlalchemy | 1.4.7 | 间接依赖 | pip |
sphinx-book-theme | 1.0.1 | 间接依赖 | pip |
ObjectId | 间接依赖 | pip | |
Evaluation | 间接依赖 | pip | |
ABC | 间接依赖 | pip | |
sqlalchemy-databricks | 0.2.0 | 间接依赖 | pip |
ChatAnthropic | 间接依赖 | pip | |
Anthropic | 间接依赖 | pip | |
dataherald | 间接依赖 | pip | |
httpx | 0.24.1 | 间接依赖 | pip |
openai | 0.27.8 | 间接依赖 | pip |
python-dotenv | 1.0.0 | 间接依赖 | pip |
List | 间接依赖 | pip | |
load-dotenv | 0.1.0 | 间接依赖 | pip |
ipdb | 0.13.13 | 间接依赖 | pip |
InvalidId | 间接依赖 | pip | |
Evaluator | 间接依赖 | pip |