基础信息
项目名称:dgraph-io/dgraph
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717140362480107520/1717140362555604992
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
低危 | ||||
urllib3 安全漏洞 | 未授权敏感信息泄露 | MPS-46py-nxai | CVE-2023-45803 | 中危 |
Gevent 安全漏洞 | MPS-d183-ymbv | CVE-2023-41419 | 严重 | |
urllib3 HTTP重定向信息泄露漏洞 | 未授权敏感信息泄露 | MPS-s0oy-afbw | CVE-2023-43804 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
urllib3 | 1.26.5 | 1.26.18 | 间接依赖 | 建议修复 |
gevent | 1.4.0 | 23.9.0 | 间接依赖 | 可选修复 |
golang.org/x/net | v0.14.0 | 0.17.0 | 直接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 55 | 低 |
BSD-2-Clause | 10 | 低 |
Apache-2.0 | 67 | 低 |
BSD-3-Clause | 35 | 低 |
ISC | 2 | 低 |
MPL-2.0 | 11 | 低 |
CC-BY-SA-4.0 | 1 | 中 |
自定义许可证 | 13 | 低 |
BSD-2-Clause-Views | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
clint | 0.5.1 | 间接依赖 | pip |
tabulate | 0.8.7 | 间接依赖 | pip |
urllib3 | 1.26.5 | 间接依赖 | pip |
github.com/graph-gophers/graphql-go | v1.3.0 | 直接依赖 | go |
requests | 2.31.0 | 间接依赖 | pip |
github.com/getsentry/sentry-go | v0.6.0 | 直接依赖 | go |
github.com/golang/protobuf | v1.5.3 | 直接依赖 | go |
graphql | 0.10.5 | 间接依赖 | npm |
github.com/subosito/gotenv | v1.4.2 | 间接依赖 | go |
github.com/pkg/errors | v0.9.1 | 直接依赖 | go |
github.com/jcmturner/rpc/v2 | v2.0.3 | 间接依赖 | go |
github.com/google/uuid | v1.3.0 | 直接依赖 | go |
github.com/xdg/stringprep | v1.0.3 | 间接依赖 | go |
go.uber.org/zap | v1.16.0 | 直接依赖 | go |
github.com/davecgh/go-spew | v1.1.1 | 间接依赖 | go |
github.com/google/go-cmp | v0.5.9 | 直接依赖 | go |
github.com/hashicorp/go-uuid | v1.0.3 | 间接依赖 | go |
github.com/DataDog/datadog-go | v3.5.0+incompatible | 间接依赖 | go |
github.com/IBM/sarama | v1.41.0 | 直接依赖 | go |
websocket-client | 0.57.0 | 间接依赖 | pip |
contrib.go.opencensus.io/exporter/jaeger | v0.1.0 | 直接依赖 | go |
github.com/blevesearch/segment | v0.9.1 | 间接依赖 | go |
github.com/dgraph-io/simdjson-go | v0.3.0 | 直接依赖 | go |
aws-sam-translator | 1.22.0 | 间接依赖 | pip |
github.com/opencontainers/go-digest | v1.0.0 | 间接依赖 | go |
github.com/philhofer/fwd | v1.0.0 | 间接依赖 | go |
github.com/klauspost/cpuid/v2 | v2.0.3 | 间接依赖 | go |
PyYAML | 5.4 | 间接依赖 | pip |
github.com/matttproud/golang_protobuf_extensions | v1.0.4 | 间接依赖 | go |
docker | 4.2.0 | 间接依赖 | pip |
MarkupSafe | 1.1.1 | 间接依赖 | pip |
github.com/hashicorp/hcl | v1.0.0 | 间接依赖 | go |
github.com/minio/sha256-simd | v0.1.1 | 间接依赖 | go |
github.com/morikuni/aec | v1.0.0 | 间接依赖 | go |
golang.org/x/net | v0.14.0 | 直接依赖 | go |
github.com/fsnotify/fsnotify | v1.6.0 | 间接依赖 | go |
github.com/agnivade/levenshtein | v1.0.3 | 间接依赖 | go |
jsonpointer | 2.0 | 间接依赖 | pip |
idna | 2.9 | 间接依赖 | pip |
gopkg.in/yaml.v3 | v3.0.1 | 间接依赖 | go |
go.opencensus.io | v0.24.0 | 直接依赖 | go |
graphql-to-json-schema | 1.0.0 | 直接依赖 | npm |
github.com/ryanuber/go-glob | v1.0.0 | 间接依赖 | go |
github.com/spf13/viper | v1.7.1 | 直接依赖 | go |
github.com/blevesearch/upsidedown_store_api | v1.0.2 | 间接依赖 | go |
golang.org/x/sync | v0.3.0 | 直接依赖 | go |
six | 1.14.0 | 间接依赖 | pip |
golang.org/x/time | v0.3.0 | 间接依赖 | go |
decorator | 4.4.2 | 间接依赖 | pip |
github.com/graph-gophers/graphql-go | v1.5.0 | 直接依赖 | go |
github.com/dgraph-io/gqlgen | v0.13.2 | 直接依赖 | go |
github.com/spf13/afero | v1.9.5 | 间接依赖 | go |
github.com/HdrHistogram/hdrhistogram-go | v1.1.2 | 直接依赖 | go |
github.com/dgraph-io/dgo/v230 | v230.0.1 | 直接依赖 | go |
github.com/google/flatbuffers | v1.12.1 | 间接依赖 | go |
github.com/hashicorp/vault/sdk | v0.1.13 | 间接依赖 | go |
chardet | 3.0.4 | 间接依赖 | pip |
github.com/go-sql-driver/mysql | v0.0.0-20190330032241-c0f6b444ad8f | 直接依赖 | go |
github.com/jcmturner/dnsutils/v2 | v2.0.0 | 间接依赖 | go |
backports.shutil-get-terminal-size | 1.0.0 | 间接依赖 | pip |
github.com/pkg/profile | v1.2.1 | 直接依赖 | go |
github.com/blevesearch/bleve/v2 | v2.3.9 | 直接依赖 | go |
github.com/spf13/pflag | v1.0.5 | 直接依赖 | go |
github.com/golang/glog | v1.1.0 | 直接依赖 | go |
github.com/jcmturner/gokrb5/v8 | v8.4.4 | 间接依赖 | go |
github.com/mitchellh/mapstructure | v1.5.0 | 间接依赖 | go |
github.com/blevesearch/go-porterstemmer | v1.0.3 | 间接依赖 | go |
github.com/cespare/xxhash/v2 | v2.2.0 | 间接依赖 | go |
github.com/klauspost/compress | v1.16.7 | 间接依赖 | go |
github.com/DataDog/opencensus-go-exporter-datadog | v0.0.0-20190503082300-0f32ad59ab08 | 直接依赖 | go |
github.com/dgraph-io/graphql-transport-ws | v0.0.0-20210511143556-2cef522f1f15 | 直接依赖 | go |
github.com/Microsoft/go-winio | v0.5.2 | 间接依赖 | go |
github.com/blevesearch/geo | v0.1.17 | 间接依赖 | go |
github.com/hashicorp/go-multierror | v1.1.1 | 间接依赖 | go |
rsa | 4.7 | 间接依赖 | pip |
github.com/eapache/queue | v1.1.0 | 间接依赖 | go |
github.com/dgraph-io/gqlparser/v2 | v2.2.1 | 直接依赖 | go |
github.com/mitchellh/go-homedir | v1.1.0 | 间接依赖 | go |
github.com/moby/term | v0.5.0 | 间接依赖 | go |
s3transfer | 0.3.3 | 间接依赖 | pip |
dataclasses-jsonschema | 2.12.0 | 间接依赖 | pip |
github.com/xdg/scram | v0.0.0-20180814205039-7eeb5667e42c | 直接依赖 | go |
github.com/mitchellh/panicwrap | v1.0.0 | 直接依赖 | go |
github.com/docker/go-connections | v0.4.0 | 直接依赖 | go |
github.com/dgraph-io/badger/v4 | v4.2.0 | 直接依赖 | go |
github.com/docker/docker | v24.0.5+incompatible | 直接依赖 | go |
google.golang.org/genproto/googleapis/rpc | v0.0.0-20230711160842-782d3b101e98 | 间接依赖 | go |
github.com/spf13/cobra | v1.7.0 | 直接依赖 | go |
github.com/pelletier/go-toml | v1.2.0 | 间接依赖 | go |
github.com/blevesearch/bleve_index_api | v1.0.5 | 间接依赖 | go |
pyasn1 | 0.4.8 | 间接依赖 | pip |
embargo | 0.1.1 | 间接依赖 | pip |
Werkzeug | 2.2.3 | 间接依赖 | pip |
taskcat | 0.9.17 | 间接依赖 | pip |
click | 7.1.2 | 间接依赖 | pip |
github.com/google/codesearch | v1.0.0 | 直接依赖 | go |
github.com/tinylib/msgp | v1.1.2 | 间接依赖 | go |
botocore | 1.15.40 | 间接依赖 | pip |
github.com/json-iterator/go | v1.1.12 | 间接依赖 | go |
gopkg.in/ini.v1 | v1.67.0 | 间接依赖 | go |
golang.org/x/text | v0.12.0 | 直接依赖 | go |
github.com/rcrowley/go-metrics | v0.0.0-20201227073835-cf1acfcdf475 | 间接依赖 | go |
yattag | 1.13.2 | 间接依赖 | pip |
go.etcd.io/etcd/raft/v3 | v3.5.9 | 直接依赖 | go |
github.com/apache/thrift | v0.13.0 | 间接依赖 | go |
networkx | 2.6 | 间接依赖 | pip |
jsonschema | 3.2.0 | 间接依赖 | pip |
jsonpatch | 1.25 | 间接依赖 | pip |
google.golang.org/grpc/examples | v0.0.0-20230821201920-d51b3f41716d | 间接依赖 | go |
boto3 | 1.12.40 | 间接依赖 | pip |
github.com/gorilla/websocket | v1.4.2 | 直接依赖 | go |
github.com/magiconair/properties | v1.8.7 | 间接依赖 | go |
github.com/spf13/cast | v1.3.0 | 直接依赖 | go |
args | 0.1.0 | 间接依赖 | pip |
mock | 2.0.0 | 间接依赖 | pip |
github.com/hashicorp/go-sockaddr | v1.0.2 | 间接依赖 | go |
github.com/dgryski/go-farm | v0.0.0-20200201041132-a6ae2369ad13 | 直接依赖 | go |
awscli | 1.18.40 | 间接依赖 | pip |
Pygments | 2.15.0 | 间接依赖 | pip |
github.com/rogpeppe/go-internal | v1.6.1 | 间接依赖 | go |
six | 1.15.0 | 间接依赖 | pip |
python-dateutil | 2.8.1 | 间接依赖 | pip |
colorama | 0.4.3 | 间接依赖 | pip |
github.com/dgraph-io/ristretto | v0.1.1 | 直接依赖 | go |
golang.org/x/mod | v0.12.0 | 间接依赖 | go |
github.com/pmezard/go-difflib | v1.0.0 | 间接依赖 | go |
typing-extensions | 3.7.4.2 | 间接依赖 | pip |
github.com/opencontainers/image-spec | v1.0.2 | 间接依赖 | go |
gopkg.in/square/go-jose.v2 | v2.3.1 | 直接依赖 | go |
go.uber.org/atomic | v1.9.0 | 间接依赖 | go |
github.com/gogo/protobuf | v1.3.2 | 直接依赖 | go |
github.com/minio/minio-go/v6 | v6.0.55 | 直接依赖 | go |
github.com/golang/geo | v0.0.0-20210211234256-740aa86cb551 | 直接依赖 | go |
reprint | 0.5.2 | 间接依赖 | pip |
contrib.go.opencensus.io/exporter/prometheus | v0.1.0 | 直接依赖 | go |
docutils | 0.15.2 | 间接依赖 | pip |
github.com/modern-go/reflect2 | v1.0.2 | 间接依赖 | go |
google.golang.org/api | v0.122.0 | 间接依赖 | go |
github.com/beorn7/perks | v1.0.1 | 间接依赖 | go |
github.com/pierrec/lz4 | v2.5.2+incompatible | 间接依赖 | go |
github.com/hashicorp/go-retryablehttp | v0.6.6 | 间接依赖 | go |
github.com/blevesearch/snowballstem | v0.9.0 | 间接依赖 | go |
github.com/docker/go-units | v0.4.0 | 间接依赖 | go |
github.com/jcmturner/gofork | v1.7.6 | 间接依赖 | go |
certifi | 2023.7.22 | 间接依赖 | pip |
github.com/hashicorp/vault/api | v1.0.4 | 直接依赖 | go |
github.com/dustin/go-humanize | v1.0.0 | 直接依赖 | go |
go.uber.org/multierr | v1.10.0 | 间接依赖 | go |
github.com/soheilhy/cmux | v0.1.4 | 直接依赖 | go |
github.com/frankban/quicktest | v1.10.2 | 间接依赖 | go |
github.com/jcmturner/aescts/v2 | v2.0.0 | 间接依赖 | go |
github.com/golang/groupcache | v0.0.0-20210331224755-41bb18bfe9da | 间接依赖 | go |
github.com/hashicorp/go-cleanhttp | v0.5.2 | 间接依赖 | go |
gotest.tools/v3 | v3.5.0 | 间接依赖 | go |
github.com/bits-and-blooms/bitset | v1.2.0 | 间接依赖 | go |
gevent | 1.4.0 | 间接依赖 | pip |
github.com/eapache/go-resiliency | v1.4.0 | 间接依赖 | go |
github.com/twpayne/go-geom | v1.0.5 | 直接依赖 | go |
iterall | 1.3.0 | 间接依赖 | npm |
github.com/dgryski/go-groupvarint | v0.0.0-20190318181831-5ce5df8ca4e1 | 直接依赖 | go |
github.com/prometheus/client_model | v0.3.0 | 间接依赖 | go |
attrs | 19.3.0 | 间接依赖 | pip |
Flask | 2.3.2 | 间接依赖 | pip |
gopkg.in/DataDog/dd-trace-go.v1 | v1.22.0 | 间接依赖 | go |
github.com/spf13/jwalterweatherman | v1.1.0 | 间接依赖 | go |
github.com/Masterminds/semver/v3 | v3.1.0 | 直接依赖 | go |
github.com/hashicorp/go-rootcerts | v1.0.2 | 间接依赖 | go |
golang.org/x/tools | v0.9.3 | 直接依赖 | go |
github.com/eapache/go-xerial-snappy | v0.0.0-20230731223053-c322873962e3 | 间接依赖 | go |
gopkg.in/yaml.v2 | v2.4.0 | 直接依赖 | go |
jmespath | 0.9.5 | 间接依赖 | pip |
google.golang.org/appengine | v1.6.7 | 间接依赖 | go |
google.golang.org/grpc | v1.56.2 | 直接依赖 | go |
github.com/prometheus/common | v0.42.0 | 间接依赖 | go |
golang.org/x/sys | v0.11.0 | 直接依赖 | go |
Jinja2 | 2.11.3 | 间接依赖 | pip |
github.com/prometheus/procfs | v0.10.1 | 间接依赖 | go |
github.com/inconshreveable/mousetrap | v1.1.0 | 间接依赖 | go |
dulwich | 0.19.15 | 间接依赖 | pip |
github.com/hashicorp/errwrap | v1.1.0 | 间接依赖 | go |
pyrsistent | 0.16.0 | 间接依赖 | pip |
google.golang.org/protobuf | v1.31.0 | 间接依赖 | go |
github.com/golang-jwt/jwt/v5 | v5.0.0 | 直接依赖 | go |
itsdangerous | 1.1.0 | 间接依赖 | pip |
mypy-extensions | 0.4.3 | 间接依赖 | pip |
github.com/prometheus/client_golang | v1.14.0 | 直接依赖 | go |
github.com/golang/snappy | v0.0.4 | 直接依赖 | go |
github.com/modern-go/concurrent | v0.0.0-20180306012644-bacd9c7ef1dd | 间接依赖 | go |
cfn-lint | 0.29.5 | 间接依赖 | pip |
github.com/docker/distribution | v2.8.2+incompatible | 间接依赖 | go |
greenlet | 0.4.15 | 间接依赖 | pip |
github.com/stretchr/testify | v1.8.4 | 直接依赖 | go |
httpie | 3.1.0 | 间接依赖 | pip |
golang.org/x/crypto | v0.12.0 | 直接依赖 | go |
golang.org/x/term | v0.11.0 | 直接依赖 | go |
github.com/paulmach/go.geojson | v0.0.0-20170327170536-40612a87147b | 直接依赖 | go |
github.com/pierrec/lz4/v4 | v4.1.18 | 间接依赖 | go |
pbr | 5.4.5 | 间接依赖 | pip |