基础信息
项目名称:education/classroom
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717406555745075200/1717406555782823936
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
jQuery 跨站脚本漏洞 | XSS | MPS-2020-15461 | CVE-2020-11023 | 中危 |
jQuery 跨站脚本漏洞 | XSS | MPS-2020-15462 | CVE-2020-11022 | 中危 |
Yargs Y18n 输入原型污染漏洞 | 动态确定对象属性修改的控制不恰当 | MPS-2020-17543 | CVE-2020-7774 | 严重 |
yargs-parser 原型污染漏洞 | 特权定义了不安全动作 | MPS-2020-4006 | CVE-2020-7608 | 中危 |
Ruy Adorno hosted-git-info 正则表达式拒绝服务漏洞 | 拒绝服务 | MPS-2021-3400 | CVE-2021-23362 | 中危 |
mem | 拒绝服务 | MPS-2022-12990 | 中危 | |
node-semver 安全漏洞 | ReDoS | MPS-2022-5166 | CVE-2022-25883 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
jquery | 3.4.1 | 3.5.0 | 直接依赖 | 建议修复 |
y18n | 3.2.1 | 3.2.2 | 间接依赖 | 建议修复 |
mem | 1.1.0 | 4.0.0 | 间接依赖 | 可选修复 |
hosted-git-info | 2.5.0 | 2.8.9 | 间接依赖 | 可选修复 |
yargs-parser | 7.0.0 | 13.1.2 | 间接依赖 | 可选修复 |
semver | 5.3.0 | 7.5.2 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 112 | 低 |
自定义许可证 | 9 | 低 |
ISC | 12 | 低 |
GPL-3.0 | 1 | 中 |
BSD-3-Clause | 2 | 低 |
Apache-2.0 | 4 | 低 |
Apache-2.0 OR MIT | 1 | 低 |
LGPL-3.0-or-later | 1 | 低 |
BSD-2-Clause | 2 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
addressable | 2.6.0 | 间接依赖 | bundler |
decamelize | 1.2.0 | 间接依赖 | npm |
string-width | 1.0.2 | 间接依赖 | npm |
crossvent | 1.5.4 | 间接依赖 | npm |
contra | 1.9.4 | 间接依赖 | npm |
ethon | 0.10.1 | 间接依赖 | bundler |
guard-rspec | 4.7.3 | 间接依赖 | bundler |
json | 2.1.0 | 间接依赖 | bundler |
execjs | 2.7.0 | 间接依赖 | bundler |
path-key | 2.0.1 | 间接依赖 | npm |
action-cable-testing | 0.3.1 | 间接依赖 | bundler |
number-is-nan | 1.0.1 | 间接依赖 | npm |
primer-forms | 2.1.8 | 间接依赖 | npm |
rspec | 3.6.0 | 间接依赖 | bundler |
flipper | 0.10.2 | 间接依赖 | bundler |
primer-table-object | 1.4.13 | 间接依赖 | npm |
omniauth-github | 1.3.0 | 间接依赖 | bundler |
rake | 12.3.3 | 间接依赖 | bundler |
primer-pagination | 1.0.7 | 间接依赖 | npm |
pg_search | 2.2.0 | 间接依赖 | bundler |
primer-popover | 0.1.8 | 间接依赖 | npm |
primer-marketing-type | 1.4.13 | 间接依赖 | npm |
faraday_middleware | 0.13.1 | 间接依赖 | bundler |
json-jwt | 1.11.0 | 间接依赖 | bundler |
lcid | 1.0.0 | 间接依赖 | npm |
primer-marketing-buttons | 1.0.13 | 间接依赖 | npm |
strip-eof | 1.0.0 | 间接依赖 | npm |
primer-base | 1.9.2 | 间接依赖 | npm |
uglifier | 4.1.20 | 间接依赖 | bundler |
rubocop | 0.49.1 | 间接依赖 | bundler |
puma | 4.3.1 | 间接依赖 | bundler |
strip-ansi | 3.0.1 | 间接依赖 | npm |
rspec-expectations | 3.6.0 | 间接依赖 | bundler |
which | 1.2.14 | 间接依赖 | npm |
rspec-support | 3.6.0 | 间接依赖 | bundler |
websocket-driver | 0.7.1 | 间接依赖 | bundler |
primer-avatars | 1.5.10 | 间接依赖 | npm |
flipper-ui | 0.10.2 | 间接依赖 | bundler |
knapsack | 1.14.1 | 间接依赖 | bundler |
mimic-fn | 1.1.0 | 间接依赖 | npm |
pry-byebug | 3.7.0 | 间接依赖 | bundler |
jquery.turbolinks | 2.1.0 | 直接依赖 | npm |
mime-types | 3.2.2 | 间接依赖 | bundler |
scss_lint | 0.54.0 | 间接依赖 | bundler |
rails-controller-testing | 1.0.4 | 间接依赖 | bundler |
rainbow | 2.2.2 | 间接依赖 | bundler |
barnes | 0.0.7 | 间接依赖 | bundler |
octicons_helper | 9.1.1 | 间接依赖 | bundler |
tiny-emitter | 2.0.1 | 间接依赖 | npm |
webcomponents.js | 0.7.24 | 直接依赖 | npm |
activemodel | 5.2.3 | 间接依赖 | bundler |
method_source | 0.8.2 | 间接依赖 | bundler |
coffee-rails | 4.2.2 | 间接依赖 | bundler |
primer-tables | 1.5.3 | 间接依赖 | npm |
bullet | 6.0.1 | 间接依赖 | bundler |
coffee-script-source | 1.12.2 | 间接依赖 | bundler |
marcel | 0.3.3 | 间接依赖 | bundler |
declarative | 0.0.10 | 间接依赖 | bundler |
kaminari | 1.0.1 | 间接依赖 | bundler |
primer-product | 5.8.3 | 间接依赖 | npm |
uber | 0.1.0 | 间接依赖 | bundler |
require-directory | 2.1.1 | 间接依赖 | npm |
diff-lcs | 1.3 | 间接依赖 | bundler |
select | 1.1.2 | 间接依赖 | npm |
read-pkg | 2.0.0 | 间接依赖 | npm |
kaminari-core | 1.0.1 | 间接依赖 | bundler |
web-console | 3.5.1 | 间接依赖 | bundler |
bindex | 0.5.0 | 间接依赖 | bundler |
os | 1.0.1 | 间接依赖 | bundler |
tzinfo | 1.2.5 | 间接依赖 | bundler |
connection_pool | 2.2.2 | 间接依赖 | bundler |
primer-tooltips | 1.5.11 | 间接依赖 | npm |
signet | 0.11.0 | 间接依赖 | bundler |
rails-html-sanitizer | 1.2.0 | 间接依赖 | bundler |
peek-pg | 1.3.0 | 间接依赖 | bundler |
bindata | 2.4.4 | 间接依赖 | bundler |
hashie | 3.6.0 | 间接依赖 | bundler |
sprockets-rails | 3.2.1 | 间接依赖 | bundler |
primer-truncate | 1.4.13 | 间接依赖 | npm |
locate-path | 2.0.0 | 间接依赖 | npm |
jquery | 3.4.1 | 直接依赖 | npm |
clipboard | 1.7.1 | 直接依赖 | npm |
actionview | 5.2.3 | 间接依赖 | bundler |
flipper-redis | 0.10.2 | 间接依赖 | bundler |
faraday-http-cache | 2.0.0 | 间接依赖 | bundler |
npm-run-path | 2.0.2 | 间接依赖 | npm |
primer-breadcrumb | 1.5.9 | 间接依赖 | npm |
primer | 10.10.5 | 直接依赖 | npm |
builder | 3.2.3 | 间接依赖 | bundler |
erubi | 1.8.0 | 间接依赖 | bundler |
hashdiff | 1.0.0 | 间接依赖 | bundler |
mini_mime | 1.0.2 | 间接依赖 | bundler |
formatador | 0.2.5 | 间接依赖 | bundler |
get-stream | 2.3.1 | 间接依赖 | npm |
coderay | 1.1.2 | 间接依赖 | bundler |
os-locale | 2.0.0 | 间接依赖 | npm |
listen | 3.1.5 | 间接依赖 | bundler |
is-fullwidth-code-point | 2.0.0 | 间接依赖 | npm |
loofah | 2.3.1 | 间接依赖 | bundler |
read-pkg-up | 2.0.0 | 间接依赖 | npm |
atoa | 1.0.0 | 间接依赖 | npm |
nio4r | 2.5.2 | 间接依赖 | bundler |
include-fragment-element | 3.0.0 | 直接依赖 | npm |
sawyer | 0.8.2 | 间接依赖 | bundler |
mem | 1.1.0 | 间接依赖 | npm |
object-assign | 4.1.1 | 间接依赖 | npm |
rails-ujs | 5.1.2 | 直接依赖 | npm |
primer-labels | 1.5.13 | 间接依赖 | npm |
primer-support | 4.7.2 | 间接依赖 | npm |
aes_key_wrap | 1.0.1 | 间接依赖 | bundler |
guard | 2.14.1 | 间接依赖 | bundler |
details-element-polyfill | 2.3.1 | 直接依赖 | npm |
kaminari-activerecord | 1.0.1 | 间接依赖 | bundler |
jquery-readyselector | 0.1.0 | 直接依赖 | npm |
primer-progress | 0.1.3 | 间接依赖 | npm |
rack-canonical-host | 0.2.3 | 间接依赖 | bundler |
activestorage | 5.2.3 | 间接依赖 | bundler |
concurrent-ruby | 1.0.5 | 间接依赖 | bundler |
load-json-file | 2.0.0 | 间接依赖 | npm |
which-module | 2.0.0 | 间接依赖 | npm |
is-builtin-module | 1.0.0 | 间接依赖 | npm |
octicons | 9.1.1 | 间接依赖 | bundler |
peek | 1.0.1 | 间接依赖 | bundler |
primer-core | 6.10.9 | 间接依赖 | npm |
faraday | 0.12.2 | 间接依赖 | bundler |
simplecov-html | 0.10.2 | 间接依赖 | bundler |
google-api-client | 0.29.1 | 间接依赖 | bundler |
httpclient | 2.8.3 | 间接依赖 | bundler |
pinglish | 0.2.1 | 间接依赖 | bundler |
sass | 3.4.25 | 间接依赖 | bundler |
retriable | 3.1.2 | 间接依赖 | bundler |
googleauth | 0.8.1 | 间接依赖 | bundler |
uniform_notifier | 1.12.1 | 间接依赖 | bundler |
multipart-post | 2.1.1 | 间接依赖 | bundler |
dragula | 3.7.1 | 直接依赖 | npm |
fuubar | 2.4.1 | 间接依赖 | bundler |
rspec-mocks | 3.6.0 | 间接依赖 | bundler |
require-main-filename | 1.0.1 | 间接依赖 | npm |
ast | 2.3.0 | 间接依赖 | bundler |
strip-ansi | 4.0.0 | 间接依赖 | npm |
factory_bot | 4.8.2 | 间接依赖 | bundler |
ruby-progressbar | 1.8.1 | 间接依赖 | bundler |
notiffany | 0.1.1 | 间接依赖 | bundler |
tilt | 2.0.8 | 间接依赖 | bundler |
railties | 5.2.3 | 间接依赖 | bundler |
normalize-package-data | 2.4.0 | 间接依赖 | npm |
primer-blankslate | 1.5.2 | 间接依赖 | npm |
pify | 2.3.0 | 间接依赖 | npm |
delegate | 3.1.3 | 间接依赖 | npm |
lograge | 0.11.2 | 间接依赖 | bundler |
i18n | 0.9.5 | 间接依赖 | bundler |
faker | 1.8.4 | 间接依赖 | bundler |
mimemagic | 0.3.3 | 间接依赖 | bundler |
geo_pattern | 1.4.0 | 间接依赖 | bundler |
shellany | 0.0.1 | 间接依赖 | bundler |
request_store | 1.4.1 | 间接依赖 | bundler |
peek-sidekiq | 1.0.4 | 间接依赖 | bundler |
find-up | 2.1.0 | 间接依赖 | npm |
activerecord | 5.2.3 | 间接依赖 | bundler |
failbot_rails | 0.5.0 | 间接依赖 | bundler |
primer-marketing | 6.3.3 | 间接依赖 | npm |
puma_worker_killer | 0.1.1 | 间接依赖 | bundler |
jsonapi-renderer | 0.2.0 | 间接依赖 | bundler |
primer-buttons | 2.6.4 | 间接依赖 | npm |
hosted-git-info | 2.5.0 | 间接依赖 | npm |
mdn-polyfills | 5.11.0 | 直接依赖 | npm |
bootsnap | 1.4.4 | 间接依赖 | bundler |
nokogiri | 1.10.5 | 间接依赖 | bundler |
@webcomponents/custom-elements | 1.2.4 | 直接依赖 | npm |
declarative-option | 0.1.0 | 间接依赖 | bundler |
rb-inotify | 0.9.10 | 间接依赖 | bundler |
crass | 1.0.5 | 间接依赖 | bundler |
wrap-ansi | 2.1.0 | 间接依赖 | npm |
representable | 3.0.4 | 间接依赖 | bundler |
strip-bom | 3.0.0 | 间接依赖 | npm |
ims-lti | 2.2.3 | 间接依赖 | bundler |
spring-watcher-listen | 2.0.1 | 间接依赖 | bundler |
multi_xml | 0.6.0 | 间接依赖 | bundler |
cliui | 3.2.0 | 间接依赖 | npm |
get-caller-file | 1.0.2 | 间接依赖 | npm |
guard-compat | 1.2.1 | 间接依赖 | bundler |
sass-rails | 5.0.6 | 间接依赖 | bundler |
path-exists | 3.0.0 | 间接依赖 | npm |
is-stream | 1.1.0 | 间接依赖 | npm |
activejob | 5.2.3 | 间接依赖 | bundler |
factory_bot_rails | 4.8.2 | 间接依赖 | bundler |
msgpack | 1.3.1 | 间接依赖 | bundler |
rspec-core | 3.6.0 | 间接依赖 | bundler |
validate-npm-package-license | 3.0.1 | 间接依赖 | npm |
primer-navigation | 1.5.11 | 间接依赖 | npm |
string-width | 2.1.0 | 间接依赖 | npm |
remodal | 1.1.1 | 直接依赖 | npm |
primer-subhead | 1.0.11 | 间接依赖 | npm |
case_transform | 0.2 | 间接依赖 | bundler |
parse-json | 2.2.0 | 间接依赖 | npm |
primer-page-sections | 1.5.3 | 间接依赖 | npm |
mime-types-data | 3.2019.0331 | 间接依赖 | bundler |
activesupport | 5.2.3 | 间接依赖 | bundler |
path-type | 2.0.0 | 间接依赖 | npm |
primer-alerts | 1.5.13 | 间接依赖 | npm |
execa | 0.5.1 | 间接依赖 | npm |
thread_safe | 0.3.6 | 间接依赖 | bundler |
atomic | 1.1.101 | 间接依赖 | bundler |
set-blocking | 2.0.0 | 间接依赖 | npm |
is-fullwidth-code-point | 1.0.0 | 间接依赖 | npm |
coffee-script | 2.4.1 | 间接依赖 | bundler |
rack | 2.0.8 | 间接依赖 | bundler |
simplecov | 0.15.0 | 间接依赖 | bundler |
get_process_mem | 0.2.4 | 间接依赖 | bundler |
p-locate | 2.0.0 | 间接依赖 | npm |
primer-layout | 1.6.2 | 间接依赖 | npm |
custom-event | 1.0.0 | 间接依赖 | npm |
primer-box | 2.5.13 | 间接依赖 | npm |
dalli | 2.7.6 | 间接依赖 | bundler |
concurrent-ruby-ext | 1.0.5 | 间接依赖 | bundler |
omniauth | 1.9.0 | 间接依赖 | bundler |
2.7.1 | 间接依赖 | bundler | |
peek-performance_bar | 1.3.1 | 间接依赖 | bundler |
rails-i18n | 5.1.3 | 间接依赖 | bundler |
dotenv | 2.7.4 | 间接依赖 | bundler |
whatwg-fetch | 2.0.3 | 直接依赖 | npm |
rack-protection | 2.0.5 | 间接依赖 | bundler |
primer-markdown | 3.7.13 | 间接依赖 | npm |
lru-cache | 4.1.1 | 间接依赖 | npm |
rb-fsevent | 0.10.2 | 间接依赖 | bundler |
spring | 2.1.0 | 间接依赖 | bundler |
color | 1.8 | 间接依赖 | bundler |
peek-gc | 0.0.2 | 间接依赖 | bundler |
arel | 9.0.0 | 间接依赖 | bundler |
statsd-ruby | 1.4.0 | 间接依赖 | bundler |
good-listener | 1.2.2 | 间接依赖 | npm |
camelcase | 4.1.0 | 间接依赖 | npm |
redis | 3.3.5 | 间接依赖 | bundler |
parser | 2.4.0.0 | 间接依赖 | bundler |
minitest | 5.13.0 | 间接依赖 | bundler |
primer-marketing-support | 1.5.6 | 间接依赖 | npm |
lumberjack | 1.0.12 | 间接依赖 | bundler |
primer-marketing-utilities | 1.7.3 | 间接依赖 | npm |
safe_yaml | 1.0.5 | 间接依赖 | bundler |
graceful-fs | 4.1.11 | 间接依赖 | npm |
oauth2 | 1.4.0 | 间接依赖 | bundler |
ffi | 1.9.24 | 间接依赖 | bundler |
signal-exit | 3.0.2 | 间接依赖 | npm |
@github/details-menu-element | 1.0.6 | 直接依赖 | npm |
webmock | 3.7.5 | 间接依赖 | bundler |
ansi-regex | 3.0.0 | 间接依赖 | npm |
turbolinks | 2.5.4 | 间接依赖 | bundler |
typhoeus | 1.3.0 | 间接依赖 | bundler |
sprockets | 3.7.2 | 间接依赖 | bundler |
public_suffix | 3.1.1 | 间接依赖 | bundler |
rack-test | 1.1.0 | 间接依赖 | bundler |
pinkie-promise | 2.0.1 | 间接依赖 | npm |
pg | 1.1.4 | 间接依赖 | bundler |
jquery-ujs | 1.2.2 | 直接依赖 | npm |
invert-kv | 1.0.0 | 间接依赖 | npm |
primer-utilities | 4.14.4 | 间接依赖 | npm |
simple_oauth | 0.3.1 | 间接依赖 | bundler |
transliteration | 1.6.2 | 直接依赖 | npm |
peek-dalli | 1.2.0 | 间接依赖 | bundler |
github-markdown-css | 3.0.1 | 直接依赖 | npm |
actioncable | 5.2.3 | 间接依赖 | bundler |
thor | 0.20.3 | 间接依赖 | bundler |
bundler | 间接依赖 | bundler | |
rails-dom-testing | 2.0.3 | 间接依赖 | bundler |
ansi-regex | 2.1.1 | 间接依赖 | npm |
p-finally | 1.0.0 | 间接依赖 | npm |
pry | 0.10.4 | 间接依赖 | bundler |
failbot | 2.0.1 | 间接依赖 | bundler |
jwt | 1.5.6 | 间接依赖 | bundler |
active_model_serializers | 0.10.7 | 间接依赖 | bundler |
erubis | 2.7.0 | 间接依赖 | bundler |
cross-spawn | 4.0.2 | 间接依赖 | npm |
primer-branch-name | 1.0.11 | 间接依赖 | npm |
multi_json | 1.13.1 | 间接依赖 | bundler |
websocket-extensions | 0.1.4 | 间接依赖 | bundler |
jquery-turbolinks | 2.1.0 | 间接依赖 | bundler |
redis-namespace | 1.5.3 | 间接依赖 | bundler |
rack-tracker | 1.11.1 | 间接依赖 | bundler |
omniauth-oauth2 | 1.4.0 | 间接依赖 | bundler |
yargs-parser | 7.0.0 | 间接依赖 | npm |
mini_portile2 | 2.4.0 | 间接依赖 | bundler |
unicode-display_width | 1.3.0 | 间接依赖 | bundler |
docile | 1.1.5 | 间接依赖 | bundler |
primer-page-headers | 1.5.3 | 间接依赖 | npm |
kaminari-actionview | 1.0.1 | 间接依赖 | bundler |
autoprefixer-rails | 7.1.3 | 间接依赖 | bundler |
ruby_dep | 1.5.0 | 间接依赖 | bundler |
actionmailer | 5.2.3 | 间接依赖 | bundler |
rspec-rails | 3.6.1 | 间接依赖 | bundler |
y18n | 3.2.1 | 间接依赖 | npm |
dotenv-rails | 2.7.4 | 间接依赖 | bundler |
nenv | 0.3.0 | 间接依赖 | bundler |
byebug | 11.0.1 | 间接依赖 | bundler |
shoulda-matchers | 4.0.0.rc1 | 间接依赖 | bundler |
yargs | 8.0.2 | 间接依赖 | npm |
ticky | 1.0.1 | 间接依赖 | npm |
rails | 5.2.3 | 间接依赖 | bundler |
sidekiq | 5.2.7 | 间接依赖 | bundler |
slop | 3.6.0 | 间接依赖 | bundler |
parallel | 1.12.0 | 间接依赖 | bundler |
code-point-at | 1.1.0 | 间接依赖 | npm |
pry-rails | 0.3.9 | 间接依赖 | bundler |
actionpack | 5.2.3 | 间接依赖 | bundler |
crack | 0.4.3 | 间接依赖 | bundler |
powerpack | 0.1.1 | 间接依赖 | bundler |
peek-git | 1.0.2 | 间接依赖 | bundler |
semver | 5.3.0 | 间接依赖 | npm |
memoist | 0.16.0 | 间接依赖 | bundler |
globalid | 0.4.2 | 间接依赖 | bundler |