基础信息
项目名称:Dataherald/dataherald
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717057910881435648/1717057911082762240
此报告由Murphysec提供
漏洞列表
| 漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
|---|---|---|---|---|
| httpx 存在输入验证不恰当漏洞 | 输入验证不恰当 | MPS-2022-14944 | 中危 | |
| OpenSSL 安全漏洞 | 过度迭代 | MPS-n3pe-ljgc | CVE-2023-3817 | 中危 |
| python-cryptography 信任管理问题漏洞 | 证书验证不恰当 | MPS-sj5m-20tf | CVE-2023-38325 | 高危 |
| langchain注入漏洞 | 注入 | MPS-x9qb-uct8 | CVE-2023-39659 | 严重 |
缺陷组件
| 组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
|---|---|---|---|---|
| cryptography | 40.0.2 | 41.0.3 | 间接依赖 | 建议修复 |
| langchain | 0.0.312 | 间接依赖 | 可选修复 | |
| httpx | 0.24.1 | 间接依赖 | 可选修复 |
许可证风险
| 许可证类型 | 相关组件 | 许可证风险 |
|---|---|---|
| MIT | 8 | 低 |
| Apache-2.0 | 8 | 低 |
| ISC | 1 | 低 |
| 自定义许可证 | 6 | 低 |
| PSF-2.0 AND (Apache-2.0 OR BSD-3-Clause) | 1 | 低 |
| BSD-3-Clause | 2 | 低 |
SBOM清单
| 组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
|---|---|---|---|
| mypy-extensions | 1.0.0 | 间接依赖 | pip |
| chromadb | 0.4.12 | 间接依赖 | pip |
| overrides | 7.3.1 | 间接依赖 | pip |
| langchain | 0.0.312 | 间接依赖 | pip |
| dnspython | 2.3.0 | 间接依赖 | pip |
| snowflake-connector-python | 3.0.4 | 间接依赖 | pip |
| pytest-dotenv | 0.5.2 | 间接依赖 | pip |
| sql-metadata | 2.8.0 | 间接依赖 | pip |
| abstractmethod | 间接依赖 | pip | |
| botocore | 1.31.38 | 间接依赖 | pip |
| Tuple | 间接依赖 | pip | |
| pymongo | 4.4.0 | 间接依赖 | pip |
| bson | 间接依赖 | pip | |
| databricks-sql-connector | 2.7.0 | 间接依赖 | pip |
| psycopg2 | 2.9.6 | 间接依赖 | pip |
| boto3 | 1.28.38 | 间接依赖 | pip |
| /app/requirements.txt | 间接依赖 | pip | |
| AlephAlpha | 间接依赖 | pip | |
| Any | 间接依赖 | pip | |
| Callable | 间接依赖 | pip | |
| pinecone-client | 2.2.2 | 间接依赖 | pip |
| PyAthena | 3.0.6 | 间接依赖 | pip |
| fastapi | 0.98.0 | 间接依赖 | pip |
| packaging | 23.1 | 间接依赖 | pip |
| Dict | 间接依赖 | pip | |
| ChatCohere | 间接依赖 | pip | |
| pydantic | 1.10.9 | 间接依赖 | pip |
| sshtunnel | 0.4.0 | 间接依赖 | pip |
| sphinx | 6.2.1 | 间接依赖 | pip |
| openapi-schema-pydantic | 1.2.4 | 间接依赖 | pip |
| cryptography | 40.0.2 | 间接依赖 | pip |
| requests | 2.31.0 | 间接依赖 | pip |
| SQLAlchemy | 1.4.49 | 间接依赖 | pip |
| sqlparse | 0.4.4 | 间接依赖 | pip |
| sqlalchemy-bigquery | 1.6.1 | 间接依赖 | pip |
| uvicorn | 0.22.0 | 间接依赖 | pip |
| snowflake-sqlalchemy | 1.4.7 | 间接依赖 | pip |
| sphinx-book-theme | 1.0.1 | 间接依赖 | pip |
| ObjectId | 间接依赖 | pip | |
| Evaluation | 间接依赖 | pip | |
| ABC | 间接依赖 | pip | |
| sqlalchemy-databricks | 0.2.0 | 间接依赖 | pip |
| ChatAnthropic | 间接依赖 | pip | |
| Anthropic | 间接依赖 | pip | |
| dataherald | 间接依赖 | pip | |
| httpx | 0.24.1 | 间接依赖 | pip |
| openai | 0.27.8 | 间接依赖 | pip |
| python-dotenv | 1.0.0 | 间接依赖 | pip |
| List | 间接依赖 | pip | |
| load-dotenv | 0.1.0 | 间接依赖 | pip |
| ipdb | 0.13.13 | 间接依赖 | pip |
| InvalidId | 间接依赖 | pip | |
| Evaluator | 间接依赖 | pip |