基础信息
项目名称:feedbin/feedbin
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1717761369608683520/1717761371970076672
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
word-wrap 安全漏洞 | ReDoS | MPS-2023-5109 | CVE-2023-26115 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
word-wrap | 1.2.3 | 1.2.4 | 间接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 5 | 低 |
自定义许可证 | 10 | 低 |
BSD-3-Clause | 3 | 低 |
MIT | 86 | 低 |
GPL-3.0 | 1 | 中 |
BSD-2-Clause | 7 | 低 |
ISC | 12 | 低 |
LGPL-3.0 | 1 | 中 |
Python-2.0 | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
builder | 3.2.4 | 间接依赖 | bundler |
rack-test | 2.1.0 | 间接依赖 | bundler |
selenium-webdriver | 4.14.0 | 间接依赖 | bundler |
@humanwhocodes/config-array | 0.11.8 | 间接依赖 | npm |
net-smtp | 0.4.0 | 间接依赖 | bundler |
connection_pool | 2.4.1 | 间接依赖 | bundler |
activejob | 7.1.1 | 间接依赖 | bundler |
esquery | 1.4.0 | 间接依赖 | npm |
http-2 | 0.11.0 | 间接依赖 | bundler |
phlex-rails | 1.0.0 | 间接依赖 | bundler |
debug | 1.8.0 | 间接依赖 | bundler |
stimulus-rails | 1.3.0 | 间接依赖 | bundler |
evernote_oauth | 0.2.3 | 间接依赖 | bundler |
faraday-httpclient | 1.0.1 | 间接依赖 | bundler |
is-path-inside | 3.0.3 | 间接依赖 | npm |
base64 | 0.1.1 | 间接依赖 | bundler |
globalid | 1.2.1 | 间接依赖 | bundler |
msgpack | 1.7.2 | 间接依赖 | bundler |
escape-string-regexp | 4.0.0 | 间接依赖 | npm |
word-wrap | 1.2.3 | 间接依赖 | npm |
fog-aws | 3.21.0 | 间接依赖 | bundler |
hetchy | 1.0.0 | 间接依赖 | bundler |
import-fresh | 3.3.0 | 间接依赖 | npm |
js-sdsl | 4.3.0 | 间接依赖 | npm |
lograge | 0.14.0 | 间接依赖 | bundler |
levn | 0.4.1 | 间接依赖 | npm |
jbuilder | 2.11.5 | 间接依赖 | bundler |
oauth | 1.1.0 | 间接依赖 | bundler |
apnotic | 1.7.1 | 间接依赖 | bundler |
mini_mime | 1.1.5 | 间接依赖 | bundler |
view_component | 3.6.0 | 间接依赖 | bundler |
librato-rails | 1.4.2 | 间接依赖 | bundler |
callsites | 3.1.0 | 间接依赖 | npm |
brace-expansion | 1.1.11 | 间接依赖 | npm |
regexp_parser | 2.8.2 | 间接依赖 | bundler |
bootsnap | 1.16.0 | 间接依赖 | bundler |
fast-levenshtein | 2.0.6 | 间接依赖 | npm |
clockwork | 3.0.2 | 间接依赖 | bundler |
rb-inotify | 0.10.1 | 间接依赖 | bundler |
2.7.1 | 间接依赖 | bundler | |
rainbow | 3.1.1 | 间接依赖 | bundler |
down | 5.4.1 | 间接依赖 | bundler |
ignore | 5.2.4 | 间接依赖 | npm |
actionview | 7.1.1 | 间接依赖 | bundler |
importmap-rails | 1.2.1 | 间接依赖 | bundler |
eslint-scope | 7.1.1 | 间接依赖 | npm |
p-limit | 3.1.0 | 间接依赖 | npm |
standard-custom | 1.0.2 | 间接依赖 | bundler |
jquery-rails | 4.6.0 | 间接依赖 | bundler |
@humanwhocodes/object-schema | 1.2.1 | 间接依赖 | npm |
resolve-from | 4.0.0 | 间接依赖 | npm |
esutils | 2.0.3 | 间接依赖 | npm |
rack-session | 1.0.1 | 间接依赖 | bundler |
execjs | 2.9.1 | 间接依赖 | bundler |
addressable | 2.8.5 | 间接依赖 | bundler |
http-cookie | 1.0.5 | 间接依赖 | bundler |
prettier-linter-helpers | 1.0.0 | 间接依赖 | npm |
rubocop-ast | 1.29.0 | 间接依赖 | bundler |
websocket-driver | 0.7.6 | 间接依赖 | bundler |
isexe | 2.0.0 | 间接依赖 | npm |
loofah | 2.21.4 | 间接依赖 | bundler |
has-flag | 4.0.0 | 间接依赖 | npm |
websocket | 1.2.10 | 间接依赖 | bundler |
rails | 间接依赖 | bundler | |
uri-js | 4.4.1 | 间接依赖 | npm |
webmock | 3.8.0 | 间接依赖 | bundler |
twitter-text | 3.1.0 | 间接依赖 | bundler |
parser | 3.2.2.4 | 间接依赖 | bundler |
acorn | 8.8.2 | 间接依赖 | npm |
minitest | 5.20.0 | 间接依赖 | bundler |
jwt | 2.7.1 | 间接依赖 | bundler |
crass | 1.0.6 | 间接依赖 | bundler |
esrecurse | 4.3.0 | 间接依赖 | npm |
idn-ruby | 0.1.5 | 间接依赖 | bundler |
ffi | 1.16.3 | 间接依赖 | bundler |
unf | 0.1.4 | 间接依赖 | bundler |
rackup | 1.0.0 | 间接依赖 | bundler |
supports-color | 7.2.0 | 间接依赖 | npm |
net-imap | 0.4.1 | 间接依赖 | bundler |
oauth-tty | 1.0.5 | 间接依赖 | bundler |
ansi-regex | 5.0.1 | 间接依赖 | npm |
fs.realpath | 1.0.0 | 间接依赖 | npm |
kgio | 2.11.4 | 间接依赖 | bundler |
snaky_hash | 2.0.1 | 间接依赖 | bundler |
grapheme-splitter | 1.0.4 | 间接依赖 | npm |
path-exists | 4.0.0 | 间接依赖 | npm |
psych | 5.1.1.1 | 间接依赖 | bundler |
erb | 4.0.3 | 间接依赖 | bundler |
strip-ansi | 6.0.1 | 间接依赖 | npm |
coffee-rails | 5.0.0 | 间接依赖 | bundler |
eslint-plugin-prettier | 4.2.1 | 直接依赖 | npm |
actionpack | 7.1.1 | 间接依赖 | bundler |
activemodel | 7.1.1 | 间接依赖 | bundler |
regexpp | 3.2.0 | 间接依赖 | npm |
bigdecimal | 3.1.4 | 间接依赖 | bundler |
json-stable-stringify-without-jsonify | 1.0.1 | 间接依赖 | npm |
raindrops | 0.20.1 | 间接依赖 | bundler |
actioncable | 7.1.1 | 间接依赖 | bundler |
ffi-compiler | 1.0.1 | 间接依赖 | bundler |
queue-microtask | 1.2.3 | 间接依赖 | npm |
minimatch | 3.1.2 | 间接依赖 | npm |
type-check | 0.4.0 | 间接依赖 | npm |
js-yaml | 4.1.0 | 间接依赖 | npm |
mime-types-data | 3.2023.1003 | 间接依赖 | bundler |
timeout | 0.4.0 | 间接依赖 | bundler |
web-push | 3.0.0 | 间接依赖 | bundler |
cgi | 0.3.6 | 间接依赖 | bundler |
htmlentities | 4.3.4 | 间接依赖 | bundler |
postmark | 1.25.0 | 间接依赖 | bundler |
debug | 4.3.4 | 间接依赖 | npm |
concat-map | 0.0.1 | 间接依赖 | npm |
nokogiri | 1.15.4-x86_64-linux | 间接依赖 | bundler |
nio4r | 2.5.9 | 间接依赖 | bundler |
formatador | 1.1.0 | 间接依赖 | bundler |
unf_ext | 0.0.8.2 | 间接依赖 | bundler |
parent-module | 1.0.1 | 间接依赖 | npm |
faraday-net_http_persistent | 1.2.0 | 间接依赖 | bundler |
ruby2_keywords | 0.0.5 | 间接依赖 | bundler |
rack | 2.2.8 | 间接依赖 | bundler |
color-convert | 2.0.1 | 间接依赖 | npm |
ajv | 6.12.6 | 间接依赖 | npm |
once | 1.4.0 | 间接依赖 | npm |
thor | 1.2.2 | 间接依赖 | bundler |
locate-path | 6.0.0 | 间接依赖 | npm |
activerecord | 7.1.1 | 间接依赖 | bundler |
tzinfo | 2.0.6 | 间接依赖 | bundler |
rdoc | 6.5.0 | 间接依赖 | bundler |
json | 2.6.3 | 间接依赖 | bundler |
deep-is | 0.1.4 | 间接依赖 | npm |
rubyzip | 2.3.2 | 间接依赖 | bundler |
multi_json | 1.15.0 | 间接依赖 | bundler |
hkdf | 1.0.0 | 间接依赖 | bundler |
reverse_markdown | 2.1.1 | 间接依赖 | bundler |
dotenv-rails | 2.8.1 | 间接依赖 | bundler |
postmark-rails | 0.22.1 | 间接依赖 | bundler |
flatted | 3.2.7 | 间接依赖 | npm |
ast | 2.4.2 | 间接依赖 | bundler |
multi_xml | 0.6.0 | 间接依赖 | bundler |
eslint-utils | 3.0.0 | 间接依赖 | npm |
evernote-thrift | 1.25.2 | 间接依赖 | bundler |
rails-dom-testing | 2.2.0 | 间接依赖 | bundler |
@humanwhocodes/module-importer | 1.0.1 | 间接依赖 | npm |
i18n | 1.14.1 | 间接依赖 | bundler |
irb | 1.8.3 | 间接依赖 | bundler |
text-table | 0.2.0 | 间接依赖 | npm |
glob | 7.2.3 | 间接依赖 | npm |
httparty | 0.21.0 | 间接依赖 | bundler |
flat-cache | 3.0.4 | 间接依赖 | npm |
faraday-net_http | 1.0.1 | 间接依赖 | bundler |
websocket-extensions | 0.1.5 | 间接依赖 | bundler |
railties | 7.1.1 | 间接依赖 | bundler |
ruby-progressbar | 1.13.0 | 间接依赖 | bundler |
path-key | 3.1.1 | 间接依赖 | npm |
activestorage | 7.1.1 | 间接依赖 | bundler |
fog-core | 2.3.0 | 间接依赖 | bundler |
eslint-visitor-keys | 3.3.0 | 间接依赖 | npm |
globals | 13.20.0 | 间接依赖 | npm |
llhttp-ffi | 0.4.0 | 间接依赖 | bundler |
strip-json-comments | 3.1.1 | 间接依赖 | npm |
net-http-persistent | 4.0.2 | 间接依赖 | bundler |
aggregate | 0.2.4 | 间接依赖 | bundler |
actionmailer | 7.1.1 | 间接依赖 | bundler |
balanced-match | 1.0.2 | 间接依赖 | npm |
actiontext | 7.1.1 | 间接依赖 | bundler |
redis-client | 0.17.0 | 间接依赖 | bundler |
faker | 3.2.1 | 间接依赖 | bundler |
yard | 0.9.34 | 间接依赖 | bundler |
sassc | 2.4.0 | 间接依赖 | bundler |
librato-metrics | 1.6.2 | 间接依赖 | bundler |
is-extglob | 2.1.1 | 间接依赖 | npm |
rubocop | 1.56.4 | 间接依赖 | bundler |
standard-performance | 1.2.1 | 间接依赖 | bundler |
faraday-rack | 1.0.0 | 间接依赖 | bundler |
mime-types | 3.5.1 | 间接依赖 | bundler |
xpath | 3.2.0 | 间接依赖 | bundler |
drb | 2.1.1 | 间接依赖 | bundler |
reline | 0.3.9 | 间接依赖 | bundler |
binding_of_caller | 1.0.0 | 间接依赖 | bundler |
punycode | 2.3.0 | 间接依赖 | npm |
fog-json | 1.2.0 | 间接依赖 | bundler |
pry | 0.14.2 | 间接依赖 | bundler |
lookbook | 2.1.1 | 间接依赖 | bundler |
coderay | 1.1.3 | 间接依赖 | bundler |
excon | 0.104.0 | 间接依赖 | bundler |
webrick | 1.8.1 | 间接依赖 | bundler |
parallel | 1.23.0 | 间接依赖 | bundler |
glob-parent | 6.0.2 | 间接依赖 | npm |
faraday-excon | 1.1.0 | 间接依赖 | bundler |
activerecord-import | 1.5.0 | 间接依赖 | bundler |
shebang-regex | 3.0.0 | 间接依赖 | npm |
coffee-script | 2.4.1 | 间接依赖 | bundler |
multipart-post | 2.3.0 | 间接依赖 | bundler |
inflight | 1.0.6 | 间接依赖 | npm |
mini_magick | 4.12.0 | 间接依赖 | bundler |
rexml | 3.2.6 | 间接依赖 | bundler |
hashdiff | 1.0.1 | 间接依赖 | bundler |
reusify | 1.0.4 | 间接依赖 | npm |
sassc-rails | 2.1.2 | 间接依赖 | bundler |
json-schema-traverse | 0.4.1 | 间接依赖 | npm |
oauth2 | 2.0.9 | 间接依赖 | bundler |
is-glob | 4.0.3 | 间接依赖 | npm |
unicorn | 6.1.0 | 间接依赖 | bundler |
eslint | 8.33.0 | 直接依赖 | npm |
p-locate | 5.0.0 | 间接依赖 | npm |
type-fest | 0.20.2 | 间接依赖 | npm |
fast-json-stable-stringify | 2.1.0 | 间接依赖 | npm |
prettier | 2.8.3 | 直接依赖 | npm |
faraday-patron | 1.0.0 | 间接依赖 | bundler |
fog-xml | 0.1.4 | 间接依赖 | bundler |
strong_migrations | 1.6.3 | 间接依赖 | bundler |
stripe_event | 2.7.0 | 间接依赖 | bundler |
optionator | 0.9.1 | 间接依赖 | npm |
htmlbeautifier | 1.4.2 | 间接依赖 | bundler |
fast-diff | 1.2.0 | 间接依赖 | npm |
tilt | 2.3.0 | 间接依赖 | bundler |
fastq | 1.15.0 | 间接依赖 | npm |
rake | 13.0.6 | 间接依赖 | bundler |
find-up | 5.0.0 | 间接依赖 | npm |
which | 2.0.2 | 间接依赖 | npm |
language_server-protocol | 3.17.0.3 | 间接依赖 | bundler |
racc | 1.7.1 | 间接依赖 | bundler |
net-pop | 0.1.2 | 间接依赖 | bundler |
erubi | 1.12.0 | 间接依赖 | bundler |
image_processing | 1.12.2 | 间接依赖 | bundler |
domain_name | 0.5.20190701 | 间接依赖 | bundler |
fast-deep-equal | 3.1.3 | 间接依赖 | npm |
faraday-em_synchrony | 1.0.0 | 间接依赖 | bundler |
standard | 1.31.2 | 间接依赖 | bundler |
estraverse | 5.3.0 | 间接依赖 | npm |
uglifier | 4.2.0 | 间接依赖 | bundler |
rb-fsevent | 0.11.2 | 间接依赖 | bundler |
run-parallel | 1.2.0 | 间接依赖 | npm |
openssl | 3.2.0 | 间接依赖 | bundler |
lodash.merge | 4.6.2 | 间接依赖 | npm |
concurrent-ruby | 1.2.2 | 间接依赖 | bundler |
natural-compare | 1.4.0 | 间接依赖 | npm |
ms | 2.1.2 | 间接依赖 | npm |
cross-spawn | 7.0.3 | 间接依赖 | npm |
stringio | 3.0.8 | 间接依赖 | bundler |
sprockets-rails | 3.4.2 | 间接依赖 | bundler |
version_gem | 1.1.3 | 间接依赖 | bundler |
rouge | 4.1.3 | 间接依赖 | bundler |
faraday | 1.10.3 | 间接依赖 | bundler |
rails-controller-testing | 1.0.5 | 间接依赖 | bundler |
responders | 3.1.1 | 间接依赖 | bundler |
inherits | 2.0.4 | 间接依赖 | npm |
autoprefixer-rails | 10.4.15.0 | 间接依赖 | bundler |
faraday-multipart | 1.0.4 | 间接依赖 | bundler |
request_store | 1.5.1 | 间接依赖 | bundler |
sprockets | 4.2.1 | 间接依赖 | bundler |
stripe | 5.55.0 | 间接依赖 | bundler |
phlex | 1.8.1 | 间接依赖 | bundler |
better_errors | 2.10.1 | 间接依赖 | bundler |
espree | 9.4.1 | 间接依赖 | npm |
crack | 0.4.5 | 间接依赖 | bundler |
mutex_m | 0.1.2 | 间接依赖 | bundler |
imurmurhash | 0.1.4 | 间接依赖 | npm |
ruby-vips | 2.1.4 | 间接依赖 | bundler |
rubocop-performance | 1.19.1 | 间接依赖 | bundler |
activesupport | 7.1.1 | 间接依赖 | bundler |
chalk | 4.1.2 | 间接依赖 | npm |
rimraf | 3.0.2 | 间接依赖 | npm |
@nodelib/fs.scandir | 2.1.5 | 间接依赖 | npm |
io-console | 0.6.0 | 间接依赖 | bundler |
ansi-styles | 4.3.0 | 间接依赖 | npm |
dotenv | 2.8.1 | 间接依赖 | bundler |
file-entry-cache | 6.0.1 | 间接依赖 | npm |
@nodelib/fs.walk | 1.2.8 | 间接依赖 | npm |
doctrine | 3.0.0 | 间接依赖 | npm |
net-protocol | 0.2.1 | 间接依赖 | bundler |
marcel | 1.0.2 | 间接依赖 | bundler |
memoizable | 0.4.2 | 间接依赖 | bundler |
debug_inspector | 1.1.0 | 间接依赖 | bundler |
method_source | 1.0.0 | 间接依赖 | bundler |
prelude-ls | 1.2.1 | 间接依赖 | npm |
zeitwerk | 2.6.12 | 间接依赖 | bundler |
public_suffix | 5.0.3 | 间接依赖 | bundler |
coffee-script-source | 1.12.2 | 间接依赖 | bundler |
listen | 3.8.0 | 间接依赖 | bundler |
unicode-display_width | 2.5.0 | 间接依赖 | bundler |
css_parser | 1.16.0 | 间接依赖 | bundler |
premailer-rails | 1.12.0 | 间接依赖 | bundler |
path-is-absolute | 1.0.1 | 间接依赖 | npm |
yocto-queue | 0.1.0 | 间接依赖 | npm |
hashie | 5.0.0 | 间接依赖 | bundler |
shebang-command | 2.0.0 | 间接依赖 | npm |
net-http2 | 0.18.5 | 间接依赖 | bundler |
sanitize | 6.1.0 | 间接依赖 | bundler |
sass-rails | 6.0.0 | 间接依赖 | bundler |
actionmailbox | 7.1.1 | 间接依赖 | bundler |
premailer | 1.21.0 | 间接依赖 | bundler |
librato-rack | 1.1.1 | 间接依赖 | bundler |
rails-html-sanitizer | 1.6.0 | 间接依赖 | bundler |
date | 3.3.3 | 间接依赖 | bundler |
@nodelib/fs.stat | 2.0.5 | 间接依赖 | npm |
tailwindcss-rails | 2.0.31-x86_64-linux | 间接依赖 | bundler |
faraday-em_http | 1.0.0 | 间接依赖 | bundler |
argparse | 2.0.1 | 间接依赖 | npm |
color-name | 1.1.4 | 间接依赖 | npm |
puma | 6.4.0 | 间接依赖 | bundler |
@eslint/eslintrc | 1.4.1 | 间接依赖 | npm |
redcarpet | 3.6.0 | 间接依赖 | bundler |
thread_safe | 0.3.6 | 间接依赖 | bundler |
faraday-retry | 1.0.3 | 间接依赖 | bundler |
lint_roller | 1.1.0 | 间接依赖 | bundler |
acorn-jsx | 5.3.2 | 间接依赖 | npm |