基础信息
项目名称:DefectDojo/django-DefectDojo
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717110679843684352/1717110680619630592
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
pdfmake | 代码注入 | MPS-2022-65554 | CVE-2022-46161 | 严重 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
pdfmake | 0.2.7 | 0.3.0-beta.1 | 直接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 187 | 低 |
ISC | 14 | 低 |
BSD-3-Clause | 12 | 低 |
自定义许可证 | 23 | 低 |
GPL-2.0 | 2 | 中 |
BSD-2-Clause | 8 | 低 |
Apache-2.0 | 12 | 低 |
Apache-2.0 OR BSD-3-Clause | 1 | 低 |
CC-BY-4.0 | 1 | 低 |
LGPL-3.0 | 2 | 中 |
Apache 2.0 | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
picomatch | 2.3.1 | 间接依赖 | npm |
drmonty-datatables-plugins | 1.10.12 | 直接依赖 | npm |
browser-resolve | 1.11.3 | 间接依赖 | npm |
vcr | 间接依赖 | pip | |
ValidationError | 间接依赖 | pip | |
run-parallel | 1.2.0 | 间接依赖 | npm |
dir-glob | 3.0.1 | 间接依赖 | npm |
BaseTestCase | 间接依赖 | pip | |
django-auditlog | 2.3.0 | 间接依赖 | pip |
Count | 间接依赖 | pip | |
unittests | 间接依赖 | pip | |
yaml | 2.2.2 | 间接依赖 | npm |
date | 间接依赖 | pip | |
clipboard | 2.0.11 | 直接依赖 | npm |
font-awesome | 4.4.0 | 间接依赖 | npm |
dateutil | 间接依赖 | pip | |
clone | 1.0.4 | 间接依赖 | npm |
buffer-equal | 0.0.1 | 间接依赖 | npm |
bootstrap-select | 1.13.18 | 直接依赖 | npm |
slash | 4.0.0 | 间接依赖 | npm |
celery | 5.3.4 | 间接依赖 | pip |
dependency-graph | 0.11.0 | 间接依赖 | npm |
optionator | 0.8.3 | 间接依赖 | npm |
datatables.net-dt | 1.13.4 | 直接依赖 | npm |
serializers | 间接依赖 | pip | |
blackduck | 1.1.0 | 间接依赖 | pip |
base64-js | 1.5.1 | 间接依赖 | npm |
uWSGI | 2.0.22 | 间接依赖 | pip |
Select | 间接依赖 | pip | |
good-listener | 1.2.2 | 间接依赖 | npm |
Sonarqube_Issue | 间接依赖 | pip | |
fontawesomefree | 6.4.2 | 间接依赖 | pip |
tiny-inflate | 1.0.3 | 间接依赖 | npm |
morris.js | 0.5.1 | 直接依赖 | npm |
fullcalendar | 3.10.5 | 直接依赖 | npm |
argon2-cffi | 23.1.0 | 间接依赖 | pip |
django-tagulous | 1.3.3 | 间接依赖 | pip |
escodegen | 1.2.0 | 间接依赖 | npm |
get-assigned-identifiers | 1.2.0 | 间接依赖 | npm |
reusify | 1.0.4 | 间接依赖 | npm |
PyJWT | 2.8.0 | 间接依赖 | pip |
fill-range | 7.0.1 | 间接依赖 | npm |
@nodelib/fs.stat | 2.0.5 | 间接依赖 | npm |
abstractmethod | 间接依赖 | pip | |
CVSS3 | 间接依赖 | pip | |
postcss-load-config | 4.0.1 | 间接依赖 | npm |
django-polymorphic | 3.1.0 | 间接依赖 | pip |
merge-source-map | 1.0.4 | 间接依赖 | npm |
@types/estree | 1.0.0 | 间接依赖 | npm |
convert-source-map | 1.9.0 | 间接依赖 | npm |
django-imagekit | 5.0.0 | 间接依赖 | pip |
ignore | 5.2.0 | 间接依赖 | npm |
Product_API_Scan_Configuration | 间接依赖 | pip | |
require-directory | 2.1.1 | 间接依赖 | npm |
safer-buffer | 2.1.2 | 间接依赖 | npm |
vcrpy | 5.1.0 | 间接依赖 | pip |
xtend | 4.0.2 | 间接依赖 | npm |
core-util-is | 1.0.3 | 间接依赖 | npm |
List | 间接依赖 | pip | |
mysqlclient | 2.1.1 | 间接依赖 | pip |
Dojo_Group_Member | 间接依赖 | pip | |
picocolors | 1.0.0 | 间接依赖 | npm |
read-cache | 1.0.0 | 间接依赖 | npm |
browserify-optional | 1.0.1 | 间接依赖 | npm |
es6-set | 0.1.6 | 间接依赖 | npm |
process-nextick-args | 2.0.1 | 间接依赖 | npm |
has-tostringtag | 1.0.0 | 间接依赖 | npm |
brfs | 2.0.2 | 间接依赖 | npm |
ansi-regex | 5.0.1 | 间接依赖 | npm |
django-fieldsignals | 0.7.0 | 间接依赖 | pip |
bootstrap | 3.4.1 | 直接依赖 | npm |
browserslist | 4.21.10 | 间接依赖 | npm |
lxml | 4.9.3 | 间接依赖 | pip |
cryptography | 41.0.4 | 间接依赖 | pip |
path-parse | 1.0.7 | 间接依赖 | npm |
@nodelib/fs.scandir | 2.1.5 | 间接依赖 | npm |
gitpython | 3.1.37 | 间接依赖 | pip |
util-deprecate | 1.0.2 | 间接依赖 | npm |
source-map | 0.6.1 | 直接依赖 | npm |
brotli | 1.3.3 | 间接依赖 | npm |
ast-transform | 0.0.0 | 间接依赖 | npm |
delegate | 3.2.0 | 间接依赖 | npm |
string-width | 4.2.3 | 间接依赖 | npm |
is_finding_groups_enabled | 间接依赖 | pip | |
google-code-prettify | 1.0.5 | 直接依赖 | npm |
color-convert | 2.0.1 | 间接依赖 | npm |
python-dateutil | 2.8.2 | 间接依赖 | pip |
NOT_ACCEPTED_FINDINGS_QUERY | 间接依赖 | pip | |
chosen-js | 1.8.7 | 直接依赖 | npm |
Test | 间接依赖 | pip | |
datatables.net-bs | 1.13.4 | 间接依赖 | npm |
is-glob | 4.0.3 | 间接依赖 | npm |
APIClient | 间接依赖 | pip | |
estraverse | 4.3.0 | 间接依赖 | npm |
esprima | 1.0.4 | 间接依赖 | npm |
minimist | 1.2.8 | 间接依赖 | npm |
readdirp | 3.6.0 | 间接依赖 | npm |
django-slack | 5.19.0 | 间接依赖 | pip |
bleach | 6.0.0 | 间接依赖 | pip |
nanoid | 3.3.6 | 间接依赖 | npm |
get_object_or_404 | 间接依赖 | pip | |
Http404 | 间接依赖 | pip | |
Finding_Template | 间接依赖 | pip | |
FileUpload | 间接依赖 | pip | |
postcss-reporter | 7.0.5 | 间接依赖 | npm |
netaddr | 0.8.0 | 间接依赖 | pip |
AnnouncementRemoveForm | 间接依赖 | pip | |
postcss | 8.4.31 | 直接依赖 | npm |
django-prometheus | 2.3.1 | 间接依赖 | pip |
@types/tern | 0.23.4 | 间接依赖 | npm |
resolve | 1.1.7 | 间接依赖 | npm |
acorn-node | 1.8.2 | 间接依赖 | npm |
es6-symbol | 3.1.3 | 间接依赖 | npm |
vcrpy-unittest | 0.1.7 | 间接依赖 | pip |
sourcemap-codec | 1.4.8 | 间接依赖 | npm |
update-browserslist-db | 1.0.11 | 间接依赖 | npm |
django-watson | 1.6.3 | 间接依赖 | pip |
lilconfig | 2.0.5 | 间接依赖 | npm |
datatables.net-buttons | 2.3.6 | 间接依赖 | npm |
html2text | 2020.1.16 | 间接依赖 | pip |
@foliojs-fork/fontkit | 1.9.1 | 间接依赖 | npm |
jquery-ui | 1.13.2 | 直接依赖 | npm |
is-arguments | 1.1.1 | 间接依赖 | npm |
django | 间接依赖 | pip | |
braces | 3.0.2 | 间接依赖 | npm |
through2 | 2.0.5 | 间接依赖 | npm |
@foliojs-fork/restructure | 2.0.2 | 间接依赖 | npm |
humanize | 4.8.0 | 间接依赖 | pip |
moment | 2.29.4 | 直接依赖 | npm |
supports-preserve-symlinks-flag | 1.0.0 | 间接依赖 | npm |
pretty-hrtime | 1.0.3 | 间接依赖 | npm |
Test_Type | 间接依赖 | pip | |
postcss-cli | 10.1.0 | 直接依赖 | npm |
source-map | 0.5.7 | 间接依赖 | npm |
deep-equal | 1.1.1 | 间接依赖 | npm |
inherits | 2.0.4 | 间接依赖 | npm |
whitenoise | 5.2.0 | 间接依赖 | pip |
jquery.cookie | 1.4.1 | 直接依赖 | npm |
HttpRequest | 间接依赖 | pip | |
defusedxml | 0.7.1 | 间接依赖 | pip |
postcss-value-parser | 4.2.0 | 间接依赖 | npm |
justgage | 1.6.1 | 直接依赖 | npm |
social-auth-app-django | 5.3.0 | 间接依赖 | pip |
strip-ansi | 6.0.1 | 间接依赖 | npm |
tiny-emitter | 2.1.0 | 间接依赖 | npm |
caniuse-lite | 1.0.30001538 | 间接依赖 | npm |
esutils | 2.0.3 | 间接依赖 | npm |
esprima | 4.0.1 | 间接依赖 | npm |
setimmediate | 1.0.5 | 间接依赖 | npm |
python-gitlab | 3.15.0 | 间接依赖 | pip |
Prefetch | 间接依赖 | pip | |
Union | 间接依赖 | pip | |
iconv-lite | 0.6.3 | 间接依赖 | npm |
graceful-fs | 4.2.10 | 间接依赖 | npm |
HttpResponse | 间接依赖 | pip | |
source-map | 0.1.43 | 直接依赖 | npm |
typedarray | 0.0.6 | 间接依赖 | npm |
is-fullwidth-code-point | 3.0.0 | 间接依赖 | npm |
social-auth-core | 4.4.2 | 间接依赖 | pip |
get-stdin | 9.0.0 | 间接依赖 | npm |
coverage | 7.3.1 | 间接依赖 | pip |
pify | 2.3.0 | 间接依赖 | npm |
Markdown | 3.4.4 | 间接依赖 | pip |
add_error_message_to_response | 间接依赖 | pip | |
concat-stream | 1.6.2 | 间接依赖 | npm |
shallow-copy | 0.0.1 | 间接依赖 | npm |
fast-glob | 3.2.11 | 间接依赖 | npm |
buffer-from | 1.1.2 | 间接依赖 | npm |
wrap-ansi | 7.0.0 | 间接依赖 | npm |
redis | 5.0.1 | 间接依赖 | pip |
fsevents | 2.3.2 | 间接依赖 | npm |
is-number | 7.0.0 | 间接依赖 | npm |
Product_Type | 间接依赖 | pip | |
ACCEPTED_FINDINGS_QUERY | 间接依赖 | pip | |
path-type | 4.0.0 | 间接依赖 | npm |
resolve | 1.22.1 | 间接依赖 | npm |
png-js | 1.0.0 | 间接依赖 | npm |
hyperlink | 21.0.0 | 间接依赖 | pip |
unicode-properties | 1.4.1 | 间接依赖 | npm |
estree-is-function | 1.0.0 | 间接依赖 | npm |
ReportFindingFilter | 间接依赖 | pip | |
typo-js | 1.2.2 | 间接依赖 | npm |
ansi-styles | 4.3.0 | 间接依赖 | npm |
django-test-migrations | 1.3.0 | 间接依赖 | pip |
is-extglob | 2.1.1 | 间接依赖 | npm |
openpyxl | 3.1.2 | 间接依赖 | pip |
APITestCase | 间接依赖 | pip | |
jquery.hotkeys | 0.2.0 | 直接依赖 | npm |
get_current_user | 间接依赖 | pip | |
has | 1.0.3 | 间接依赖 | npm |
anymatch | 3.1.2 | 间接依赖 | npm |
@types/marked | 4.0.8 | 间接依赖 | npm |
codemirror-spell-checker | 1.1.2 | 间接依赖 | npm |
datatables.net | 1.13.4 | 直接依赖 | npm |
crum | 间接依赖 | pip | |
jquery.flot.tooltip | 0.9.0 | 直接依赖 | npm |
JUMFlot | 0.0.0 | 直接依赖 | npm |
user_passes_test | 间接依赖 | pip | |
JSON-log-formatter | 0.5.2 | 间接依赖 | pip |
ObjectDoesNotExist | 间接依赖 | pip | |
fs-extra | 11.0.0 | 间接依赖 | npm |
yargs-parser | 21.0.1 | 间接依赖 | npm |
System_Settings | 间接依赖 | pip | |
get_unit_tests_path | 间接依赖 | pip | |
select | 1.1.2 | 间接依赖 | npm |
startbootstrap-sb-admin-2 | 1.0.7 | 直接依赖 | npm |
jquery-highlight | 3.5.0 | 直接依赖 | npm |
chosen-bootstrap | 0.0.0 | 直接依赖 | npm |
Endpoint | 间接依赖 | pip | |
DojoTestCase | 间接依赖 | pip | |
unicode-trie | 2.0.0 | 间接依赖 | npm |
xlrd | 1.2.0 | 间接依赖 | pip |
vobject | 0.9.6.1 | 间接依赖 | pip |
django-debug-toolbar-request-history | 0.1.4 | 间接依赖 | pip |
metismenu | 3.0.7 | 直接依赖 | npm |
django-debug-toolbar | 4.2.0 | 间接依赖 | pip |
static-module | 3.0.4 | 间接依赖 | npm |
django_extensions | 3.2.3 | 间接依赖 | pip |
xmldoc | 1.2.0 | 间接依赖 | npm |
bootstrap-social | 4.11.0 | 直接依赖 | npm |
function-bind | 1.1.1 | 间接依赖 | npm |
datatables.net-colreorder | 1.6.2 | 直接依赖 | npm |
immediate | 3.0.6 | 间接依赖 | npm |
login_required | 间接依赖 | pip | |
dash-ast | 2.0.1 | 间接依赖 | npm |
flot | 0.8.3 | 直接依赖 | npm |
define-properties | 1.2.0 | 间接依赖 | npm |
static-eval | 2.1.0 | 间接依赖 | npm |
thenby | 1.3.4 | 间接依赖 | npm |
marked | 4.2.12 | 间接依赖 | npm |
pdfmake | 0.2.7 | 直接依赖 | npm |
array-from | 2.1.1 | 间接依赖 | npm |
jsonfile | 6.1.0 | 间接依赖 | npm |
render | 间接依赖 | pip | |
call-bind | 1.0.2 | 间接依赖 | npm |
is-core-module | 2.11.0 | 间接依赖 | npm |
django-environ | 0.11.2 | 间接依赖 | pip |
psycopg2-binary | 2.9.8 | 间接依赖 | pip |
codemirror | 5.65.12 | 间接依赖 | npm |
normalize-range | 0.1.2 | 间接依赖 | npm |
@foliojs-fork/pdfkit | 0.13.0 | 间接依赖 | npm |
cpe | 1.2.1 | 间接依赖 | pip |
yargs | 17.5.1 | 间接依赖 | npm |
django-crum | 0.7.9 | 间接依赖 | pip |
@types/codemirror | 5.60.7 | 间接依赖 | npm |
titlecase | 2.4.1 | 间接依赖 | pip |
object-inspect | 1.12.3 | 间接依赖 | npm |
asteval | 0.9.31 | 间接依赖 | pip |
duplexer2 | 0.1.4 | 间接依赖 | npm |
@foliojs-fork/linebreak | 1.1.1 | 间接依赖 | npm |
djangosaml2 | 1.7.0 | 间接依赖 | pip |
ProductTest | 间接依赖 | pip | |
dojo | 间接依赖 | pip | |
source-map-js | 1.0.2 | 间接依赖 | npm |
quote-stream | 1.0.2 | 间接依赖 | npm |
Dict | 间接依赖 | pip | |
CVSS2 | 间接依赖 | pip | |
magic-string | 0.25.1 | 间接依赖 | npm |
djangorestframework | 3.14.0 | 间接依赖 | pip |
amdefine | 1.0.1 | 间接依赖 | npm |
django-split-settings | 1.2.0 | 间接依赖 | pip |
escodegen | 1.14.3 | 间接依赖 | npm |
fraction.js | 4.3.6 | 间接依赖 | npm |
split_settings | 间接依赖 | pip | |
binary-extensions | 2.2.0 | 间接依赖 | npm |
SLA_Configuration | 间接依赖 | pip | |
vulners | 2.1.0 | 间接依赖 | pip |
sax | 1.2.4 | 间接依赖 | npm |
CVSS3RHScoreDoesNotMatch | 间接依赖 | pip | |
through | 2.3.8 | 间接依赖 | npm |
normalize-path | 3.0.0 | 间接依赖 | npm |
string_decoder | 1.1.1 | 间接依赖 | npm |
auditlog | 间接依赖 | pip | |
cvss | 2.6 | 间接依赖 | pip |
WaitForPageLoad | 间接依赖 | pip | |
assign_user_to_groups | 间接依赖 | pip | |
WebDriverWait | 间接依赖 | pip | |
readable-stream | 2.3.8 | 间接依赖 | npm |
Finding | 间接依赖 | pip | |
cliui | 7.0.4 | 间接依赖 | npm |
cleanup_old_groups_for_user | 间接依赖 | pip | |
object-keys | 1.1.1 | 间接依赖 | npm |
y18n | 5.0.8 | 间接依赖 | npm |
Q | 间接依赖 | pip | |
object-is | 1.1.5 | 间接依赖 | npm |
@nodelib/fs.walk | 1.2.8 | 间接依赖 | npm |
font-awesome | 4.7.0 | 直接依赖 | npm |
electron-to-chromium | 1.4.490 | 间接依赖 | npm |
PermissionDenied | 间接依赖 | pip | |
supervisor | 4.2.5 | 间接依赖 | pip |
permissions | 间接依赖 | pip | |
merge2 | 1.4.1 | 间接依赖 | npm |
Engagement | 间接依赖 | pip | |
PyGithub | 1.58.2 | 间接依赖 | pip |
get-caller-file | 2.0.5 | 间接依赖 | npm |
django-dbbackup | 4.0.2 | 间接依赖 | pip |
urllib3 | 1.26.18 | 间接依赖 | pip |
jquery | 3.7.0 | 直接依赖 | npm |
selenium | 间接依赖 | pip | |
regexp.prototype.flags | 1.4.3 | 间接依赖 | npm |
acorn-walk | 7.2.0 | 间接依赖 | npm |
emoji-regex | 8.0.0 | 间接依赖 | npm |
escalade | 3.1.1 | 间接依赖 | npm |
drf-spectacular | 0.26.5 | 间接依赖 | pip |
node-releases | 2.0.13 | 间接依赖 | npm |
Set | 间接依赖 | pip | |
HttpResponseRedirect | 间接依赖 | pip | |
globby | 13.1.2 | 间接依赖 | npm |
BurpRawRequestResponse | 间接依赖 | pip | |
on_exception_html_source_logger | 间接依赖 | pip | |
glob-parent | 5.1.2 | 间接依赖 | npm |
requests | 2.31.0 | 间接依赖 | pip |
django-ratelimit | 4.1.0 | 间接依赖 | pip |
flot-axis | 0.0.0 | 直接依赖 | npm |
functions-have-names | 1.2.3 | 间接依赖 | npm |
es6-map | 0.1.5 | 间接依赖 | npm |
is-binary-path | 2.1.0 | 间接依赖 | npm |
universalify | 2.0.0 | 间接依赖 | npm |
to-regex-range | 5.0.1 | 间接依赖 | npm |
Product_Member | 间接依赖 | pip | |
safe-buffer | 5.1.2 | 间接依赖 | npm |
micromatch | 4.0.5 | 间接依赖 | npm |
ABC | 间接依赖 | pip | |
datatables.net-buttons-dt | 2.3.6 | 直接依赖 | npm |
ast-types | 0.7.8 | 间接依赖 | npm |
packageurl-python | 0.11.2 | 间接依赖 | pip |
Dojo_Group | 间接依赖 | pip | |
AnnouncementCreateForm | 间接依赖 | pip | |
acorn | 7.4.1 | 间接依赖 | npm |
get_system_setting | 间接依赖 | pip | |
CVSS3RHMalformedError | 间接依赖 | pip | |
django-filter | 23.3 | 间接依赖 | pip |
lie | 3.3.0 | 间接依赖 | npm |
pytz | 2023.3.post1 | 间接依赖 | pip |
base64-js | 1.3.1 | 间接依赖 | npm |
isarray | 1.0.0 | 间接依赖 | npm |
EndpointFilter | 间接依赖 | pip | |
fastq | 1.13.0 | 间接依赖 | npm |
rest_framework | 间接依赖 | pip | |
pako | 0.2.9 | 间接依赖 | npm |
raphael | 2.3.0 | 间接依赖 | npm |
Tool_Configuration | 间接依赖 | pip | |
eve-raphael | 0.5.0 | 间接依赖 | npm |
bootstrap-wysiwyg | 2.0.1 | 直接依赖 | npm |
scope-analyzer | 2.1.2 | 间接依赖 | npm |
drmonty-datatables-responsive | 1.0.6 | 直接依赖 | npm |
Django | 4.1.11 | 间接依赖 | pip |
drf_yasg | 1.21.5 | 间接依赖 | pip |
datatables.net-buttons-bs | 2.3.6 | 直接依赖 | npm |
pako | 1.0.11 | 间接依赖 | npm |
jira | 3.5.2 | 间接依赖 | pip |
jszip | 3.10.1 | 直接依赖 | npm |
User | 间接依赖 | pip | |
django_celery_results | 2.5.1 | 间接依赖 | pip |
Risk_Acceptance | 间接依赖 | pip | |
dfa | 1.2.0 | 间接依赖 | npm |
is-date-object | 1.0.5 | 间接依赖 | npm |
is-regex | 1.1.4 | 间接依赖 | npm |
Tool_Type | 间接依赖 | pip | |
django-crispy-forms | 2.0 | 间接依赖 | pip |
easymde | 2.18.0 | 直接依赖 | npm |
debugpy | 1.8.0 | 间接依赖 | pip |
Python-jose | 3.3.0 | 间接依赖 | pip |
Product | 间接依赖 | pip | |
JsonResponse | 间接依赖 | pip | |
crypto-js | 4.1.1 | 间接依赖 | npm |
chokidar | 3.5.3 | 间接依赖 | npm |
gunicorn | 21.2.0 | 间接依赖 | pip |
autoprefixer | 10.4.16 | 直接依赖 | npm |