基础信息
项目名称:bjf-fhe/apicat
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717160562428526592/1717160562655019008
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
低危 | ||||
Google Golang 资源管理错误漏洞 | MPS-2022-58307 | CVE-2022-41723 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
golang.org/x/net | v0.0.0-20221014081412-f15817d10f9b | 0.17.0 | 间接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 22 | 低 |
Apache-2.0 | 46 | 低 |
BSD-3-Clause | 11 | 低 |
MPL-2.0 | 1 | 低 |
BSD-2-Clause | 2 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
github.com/mailru/easyjson | v0.7.7 | 间接依赖 | go |
github.com/alibabacloud-go/sls-20201230/v2 | v2.0.2 | 间接依赖 | go |
github.com/aliyun/credentials-go | v1.1.2 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/sso | v1.11.28 | 间接依赖 | go |
github.com/jmespath/go-jmespath | v0.4.0 | 间接依赖 | go |
github.com/alibabacloud-go/tea | v1.1.20 | 间接依赖 | go |
github.com/spf13/cast | v1.5.0 | 间接依赖 | go |
golang.org/x/sys | v0.2.0 | 间接依赖 | go |
github.com/alibabacloud-go/tea-xml | v1.1.2 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/internal/configsources | v1.1.27 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream | v1.4.10 | 间接依赖 | go |
github.com/golang/protobuf | v1.5.2 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-string | v1.0.2 | 间接依赖 | go |
github.com/spf13/pflag | v1.0.5 | 间接依赖 | go |
github.com/extrame/tail | v0.0.0-20221130014719-de0d21771c35 | 间接依赖 | go |
google.golang.org/grpc | v1.50.1 | 直接依赖 | go |
github.com/invopop/yaml | v0.1.0 | 间接依赖 | go |
github.com/perimeterx/marshmallow | v1.1.4 | 间接依赖 | go |
github.com/mitchellh/mapstructure | v1.5.0 | 间接依赖 | go |
github.com/extrame/pflag | v0.0.1 | 间接依赖 | go |
github.com/pelletier/go-toml | v1.9.5 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/credentials | v1.13.7 | 间接依赖 | go |
golang.org/x/text | v0.4.0 | 间接依赖 | go |
github.com/subosito/gotenv | v1.4.1 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url | v1.9.21 | 间接依赖 | go |
github.com/spf13/cobra | v1.6.1 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/internal/v4a | v1.0.18 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding | v1.9.11 | 间接依赖 | go |
google.golang.org/genproto | v0.0.0-20221024183307-1bc688fe9f3e | 间接依赖 | go |
github.com/alibabacloud-go/alibabacloud-gateway-spi | v0.0.4 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-array | v0.0.2 | 间接依赖 | go |
github.com/alibabacloud-go/debug | v0.0.0-20190504072949-9472017b5c68 | 间接依赖 | go |
github.com/json-iterator/go | v1.1.12 | 间接依赖 | go |
github.com/alibabacloud-go/tea-utils/v2 | v2.0.0 | 间接依赖 | go |
github.com/alibabacloud-go/openapi-util | v0.0.11 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-openapi/v2 | v2.0.2 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/internal/checksum | v1.1.22 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/config | v1.18.7 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/feature/ec2/imds | v1.12.21 | 间接依赖 | go |
github.com/alibabacloud-go/alibabacloud-gateway-sls | v0.0.5 | 间接依赖 | go |
gopkg.in/ini.v1 | v1.67.0 | 间接依赖 | go |
github.com/pelletier/go-toml/v2 | v2.0.5 | 间接依赖 | go |
github.com/getkin/kin-openapi | v0.114.0 | 间接依赖 | go |
github.com/mohae/deepcopy | v0.0.0-20170929034955-c48cc78d4826 | 间接依赖 | go |
github.com/inconshreveable/mousetrap | v1.0.1 | 间接依赖 | go |
gopkg.in/yaml.v3 | v3.0.1 | 间接依赖 | go |
github.com/tjfoc/gmsm | v1.4.1 | 间接依赖 | go |
github.com/alibabacloud-go/tea-utils | v1.4.5 | 间接依赖 | go |
gopkg.in/tomb.v1 | v1.0.0-20140529071818-c131134a1947 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/ec2 | v1.77.0 | 间接依赖 | go |
golang.org/x/net | v0.0.0-20221014081412-f15817d10f9b | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-openapi | v0.2.1 | 间接依赖 | go |
github.com/alibabacloud-go/sls-20201230 | v1.5.1 | 间接依赖 | go |
google.golang.org/protobuf | v1.28.1 | 直接依赖 | go |
gopkg.in/yaml.v2 | v2.4.0 | 间接依赖 | go |
github.com/alibabacloud-go/endpoint-util | v1.1.0 | 间接依赖 | go |
github.com/boltdb/bolt | v1.3.1 | 间接依赖 | go |
github.com/alibabacloud-go/slb-20140515/v3 | v3.3.17 | 间接依赖 | go |
github.com/spf13/jwalterweatherman | v1.1.0 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-signature-util | v0.0.6 | 间接依赖 | go |
github.com/hashicorp/hcl | v1.0.0 | 间接依赖 | go |
github.com/modern-go/reflect2 | v1.0.2 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/internal/s3shared | v1.13.21 | 间接依赖 | go |
github.com/spf13/viper | v1.14.0 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 | v2.4.21 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2 | v1.17.3 | 间接依赖 | go |
github.com/magiconair/properties | v1.8.6 | 间接依赖 | go |
github.com/pkg/errors | v0.9.1 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-map | v0.0.2 | 间接依赖 | go |
gopkg.in/fsnotify.v1 | v1.4.7 | 间接依赖 | go |
github.com/denisbrodbeck/machineid | v1.0.1 | 间接依赖 | go |
github.com/aws/smithy-go | v1.13.5 | 间接依赖 | go |
github.com/modern-go/concurrent | v0.0.0-20180306012644-bacd9c7ef1dd | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/internal/ini | v1.3.28 | 间接依赖 | go |
github.com/go-openapi/jsonpointer | v0.19.5 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/sts | v1.17.7 | 间接依赖 | go |
github.com/satyrius/gonx | v1.4.0 | 间接依赖 | go |
github.com/fsnotify/fsnotify | v1.6.0 | 间接依赖 | go |
github.com/alibabacloud-go/darabonba-encode-util | v0.0.1 | 间接依赖 | go |
github.com/clbanning/mxj/v2 | v2.5.6 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/ssooidc | v1.13.11 | 间接依赖 | go |
github.com/sirupsen/logrus | v1.9.0 | 间接依赖 | go |
github.com/spf13/afero | v1.9.2 | 间接依赖 | go |
github.com/aws/aws-sdk-go-v2/service/s3 | v1.29.6 | 间接依赖 | go |
github.com/go-openapi/swag | v0.19.5 | 间接依赖 | go |
github.com/josharian/intern | v1.0.0 | 间接依赖 | go |