HDInnovations/UNIT3D-Community-Edition 软件分析报告

基础信息

项目名称:HDInnovations/UNIT3D-Community-Edition

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1718526360314052608/1718526360532156416

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Socketio Engineio 资源管理错误漏洞 拒绝服务 MPS-2021-0191 CVE-2020-36048 高危
Laravel v9.1.8 反序列化漏洞 反序列化 MPS-2022-10162 CVE-2022-30778 严重
tough-cookie 安全漏洞 原型污染 MPS-2023-5130 CVE-2023-26136 严重
request SSRF防御绕过漏洞 SSRF MPS-2023-7722 CVE-2023-28155 中危
tough-cookie 原型污染 MPS-esyq-56vx 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
laravel/framework v10.26.2 间接依赖 强烈建议修复
tough-cookie 2.5.0 4.1.3 间接依赖 建议修复
engine.io 3.6.1 6.4.2 间接依赖 建议修复
request 2.88.2 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 260
Apache-2.0 9
Unlicense 2
BSD-2-Clause 2
0BSD 1
GPL-3.0 2
BSD-3-Clause 9
BSD-4-Clause 3
ISC 16
LGPL-2.0 2
GPL-2.0 1
SDK 1
APACHE-2.0 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
socket.io-parser 3.3.3 间接依赖 npm
symfony/polyfill-php80 v1.28.0 间接依赖 composer
laravel/serializable-closure v1.3.1 间接依赖 composer
ws 7.4.6 间接依赖 npm
escape-html 1.0.3 间接依赖 npm
ansi-styles 4.3.0 间接依赖 npm
illuminate/collections 间接依赖 composer
denque 1.5.1 间接依赖 npm
@types/node 14.18.63 间接依赖 npm
tweetnacl 0.14.5 间接依赖 npm
symfony/mailer v6.3.5 间接依赖 composer
psr/http-message 2.0 间接依赖 composer
function-bind 1.1.1 间接依赖 npm
dragonmantank/cron-expression v3.3.3 间接依赖 composer
illuminate/validation 间接依赖 composer
dotenv 8.6.0 间接依赖 npm
illuminate/database 间接依赖 composer
redis-commands 1.7.0 间接依赖 npm
color-convert 2.0.1 间接依赖 npm
@vue/shared 3.1.5 间接依赖 npm
tmp 0.0.33 间接依赖 npm
tslib 1.14.1 间接依赖 npm
path-to-regexp 0.1.7 间接依赖 npm
voku/portable-ascii 2.0.1 间接依赖 composer
spatie/laravel-cookie-consent 3.2.4 间接依赖 composer
psr/http-client 1.0.3 间接依赖 composer
composer-runtime-api 间接依赖 composer
delayed-stream 1.0.0 间接依赖 npm
spatie/laravel-image-optimizer 1.7.1 间接依赖 composer
core-util-is 1.0.2 间接依赖 npm
locate-path 5.0.0 间接依赖 npm
jsprim 1.4.2 间接依赖 npm
psr/simple-cache 3.0.0 间接依赖 composer
spatie/db-dumper 3.4.0 间接依赖 composer
intervention/image 2.7.2 间接依赖 composer
bjeavons/zxcvbn-php 1.3.1 间接依赖 composer
fresh 0.5.2 间接依赖 npm
vlucas/phpdotenv v5.5.0 间接依赖 composer
require-directory 2.1.1 间接依赖 npm
tough-cookie 2.5.0 间接依赖 npm
engine.io 3.6.1 间接依赖 npm
colors 1.4.0 间接依赖 npm
rxjs 6.6.7 间接依赖 npm
unpipe 1.0.0 间接依赖 npm
graham-campbell/result-type v1.1.1 间接依赖 composer
asynckit 0.4.0 间接依赖 npm
debug 4.3.4 间接依赖 npm
symfony/string v6.3.5 间接依赖 composer
require-main-filename 2.0.0 间接依赖 npm
symfony/polyfill-ctype v1.28.0 间接依赖 composer
string-width 4.2.3 间接依赖 npm
spatie/ssl-certificate 2.6.1 间接依赖 composer
cookie-signature 1.0.6 间接依赖 npm
virtual-select-plugin 1.0.40 间接依赖 npm
backo2 1.0.2 间接依赖 npm
ezyang/htmlpurifier v4.13.0 间接依赖 composer
symfony/http-foundation v6.3.5 间接依赖 composer
ansi-regex 5.0.1 间接依赖 npm
debug 4.1.1 间接依赖 npm
lodash.isarguments 3.1.0 间接依赖 npm
paragonie/constant_time_encoding v2.6.3 间接依赖 composer
yargs 15.4.1 间接依赖 npm
illuminate/events 间接依赖 composer
p-limit 2.3.0 间接依赖 npm
emoji-regex 8.0.0 间接依赖 npm
illuminate/config 间接依赖 composer
doctrine/dbal 3.7.0 间接依赖 composer
json-schema 0.4.0 间接依赖 npm
nette/schema v1.2.5 间接依赖 composer
psl 1.9.0 间接依赖 npm
symfony/uid v6.3.0 间接依赖 composer
symfony/service-contracts v3.3.0 间接依赖 composer
tweetnacl 1.0.3 间接依赖 npm
debug 2.6.9 间接依赖 npm
league/flysystem-local 3.16.0 间接依赖 composer
safer-buffer 2.1.2 间接依赖 npm
lodash.flatten 4.4.0 间接依赖 npm
qs 6.11.0 间接依赖 npm
onetime 5.1.2 间接依赖 npm
has-flag 4.0.0 间接依赖 npm
spatie/temporary-directory 2.2.0 间接依赖 composer
symfony/css-selector v6.3.2 间接依赖 composer
toidentifier 1.0.1 间接依赖 npm
fast-deep-equal 3.1.3 间接依赖 npm
symfony/polyfill-intl-grapheme v1.28.0 间接依赖 composer
ms 2.0.0 间接依赖 npm
symfony/event-dispatcher-contracts v3.3.0 间接依赖 composer
parseqs 0.0.6 间接依赖 npm
escape-string-regexp 1.0.5 间接依赖 npm
assada/laravel-achievements v2.6.0 间接依赖 composer
p-try 2.2.0 间接依赖 npm
negotiator 0.6.3 间接依赖 npm
ioredis 4.28.5 间接依赖 npm
har-validator 5.1.5 间接依赖 npm
symfony/polyfill-iconv v1.28.0 间接依赖 composer
object-inspect 1.12.3 间接依赖 npm
yargs-parser 18.1.3 间接依赖 npm
send 0.18.0 间接依赖 npm
ms 2.1.3 间接依赖 npm
supports-color 7.2.0 间接依赖 npm
isstream 0.1.2 间接依赖 npm
oauth-sign 0.9.0 间接依赖 npm
bytes 3.1.2 间接依赖 npm
cli-width 3.0.0 间接依赖 npm
ipaddr.js 1.9.1 间接依赖 npm
psy/psysh v0.11.21 间接依赖 composer
symfony/translation v6.3.3 间接依赖 composer
tunnel-agent 0.6.0 间接依赖 npm
serve-static 1.15.0 间接依赖 npm
has-proto 1.0.1 间接依赖 npm
illuminate/notifications 间接依赖 composer
socket.io 2.5.0 间接依赖 npm
psr/event-dispatcher 1.0.0 间接依赖 composer
nikic/php-parser v4.17.1 间接依赖 composer
voku/portable-utf8 6.0.13 间接依赖 composer
range-parser 1.2.1 间接依赖 npm
psr/container 2.0.2 间接依赖 composer
body-parser 1.20.1 间接依赖 npm
illuminate/filesystem 间接依赖 composer
ralouphie/getallheaders 3.0.3 间接依赖 composer
hdvinnie/laravel-joypixel-emojis v2.0.0 间接依赖 composer
etag 1.8.1 间接依赖 npm
psr/http-factory 1.0.2 间接依赖 composer
assert-plus 1.0.0 间接依赖 npm
chardet 0.7.0 间接依赖 npm
sshpk 1.17.0 间接依赖 npm
engine.io-client 3.5.3 间接依赖 npm
joypixels/assets v7.0.1 间接依赖 composer
theodorejb/polycast dev-master 间接依赖 composer
forever-agent 0.6.1 间接依赖 npm
psr/log 3.0.0 间接依赖 composer
guzzlehttp/promises 2.0.1 间接依赖 composer
mime-types 2.1.35 间接依赖 npm
guzzlehttp/guzzle 7.8.0 间接依赖 composer
get-intrinsic 1.2.1 间接依赖 npm
cookie 0.4.2 间接依赖 npm
methods 1.1.2 间接依赖 npm
laravel/prompts v0.1.11 间接依赖 composer
restore-cursor 3.1.0 间接依赖 npm
@types/node 20.8.2 间接依赖 npm
combined-stream 1.0.8 间接依赖 npm
lodash 4.17.21 间接依赖 npm
symfony/polyfill-intl-idn v1.28.0 间接依赖 composer
is-fullwidth-code-point 3.0.0 间接依赖 npm
content-type 1.0.5 间接依赖 npm
decamelize 1.2.0 间接依赖 npm
punycode 2.3.0 间接依赖 npm
xmlhttprequest-ssl 1.6.3 间接依赖 npm
phpoption/phpoption 1.9.1 间接依赖 composer
@types/qs 6.9.8 间接依赖 npm
aws-sign2 0.7.0 间接依赖 npm
illuminate/console 间接依赖 composer
ajv 6.12.6 间接依赖 npm
figures 3.2.0 间接依赖 npm
doctrine/inflector 2.0.8 间接依赖 composer
guzzlehttp/uri-template v1.0.2 间接依赖 composer
doctrine/lexer 3.0.0 间接依赖 composer
side-channel 1.0.4 间接依赖 npm
finalhandler 1.2.0 间接依赖 npm
y18n 4.0.3 间接依赖 npm
standard-as-callback 2.1.0 间接依赖 npm
call-bind 1.0.2 间接依赖 npm
symfony/mime v6.3.5 间接依赖 composer
illuminate/contracts 间接依赖 composer
symfony/translation-contracts v3.3.0 间接依赖 composer
symfony/process v6.3.4 间接依赖 composer
content-disposition 0.5.4 间接依赖 npm
socket.io-adapter 1.1.2 间接依赖 npm
arraybuffer.slice 0.0.7 间接依赖 npm
psr/cache 3.0.0 间接依赖 composer
http-errors 2.0.0 间接依赖 npm
doctrine/cache 2.2.0 间接依赖 composer
find-up 4.1.0 间接依赖 npm
signal-exit 3.0.7 间接依赖 npm
dflydev/dot-access-data v3.0.2 间接依赖 composer
strip-ansi 6.0.1 间接依赖 npm
symfony/finder v6.3.5 间接依赖 composer
after 0.8.2 间接依赖 npm
setprototypeof 1.2.0 间接依赖 npm
monolog/monolog 3.4.0 间接依赖 composer
ee-first 1.1.1 间接依赖 npm
laravel-echo-server 1.6.3 间接依赖 npm
p-map 2.1.0 间接依赖 npm
symfony/error-handler v6.3.5 间接依赖 composer
fast-json-stable-stringify 2.1.0 间接依赖 npm
depd 2.0.0 间接依赖 npm
destroy 1.2.0 间接依赖 npm
color-name 1.1.4 间接依赖 npm
engine.io-parser 2.2.1 间接依赖 npm
marcreichel/igdb-laravel 3.8.1 间接依赖 composer
asn1 0.2.6 间接依赖 npm
ramsey/uuid 4.7.4 间接依赖 composer
laravel/framework v10.26.2 间接依赖 composer
debug 3.1.0 间接依赖 npm
ansi-escapes 4.3.2 间接依赖 npm
spatie/laravel-signal-aware-command 1.3.0 间接依赖 composer
illuminate/cookie 间接依赖 composer
uuid 3.4.0 间接依赖 npm
through 2.3.8 间接依赖 npm
har-schema 2.0.0 间接依赖 npm
path-exists 4.0.0 间接依赖 npm
encodeurl 1.0.2 间接依赖 npm
cluster-key-slot 1.1.2 间接依赖 npm
dashdash 1.14.1 间接依赖 npm
redis-parser 3.0.0 间接依赖 npm
cliui 6.0.0 间接依赖 npm
spatie/image-optimizer 1.7.1 间接依赖 composer
symfony/polyfill-php83 v1.28.0 间接依赖 composer
blob 0.0.5 间接依赖 npm
type-is 1.6.18 间接依赖 npm
hdvinnie/laravel-html-purifier v2.0.0 间接依赖 composer
symfony/polyfill-intl-normalizer v1.28.0 间接依赖 composer
symfony/http-kernel v6.3.5 间接依赖 composer
performance-now 2.1.0 间接依赖 npm
spatie/laravel-package-tools 1.16.1 间接依赖 composer
bcrypt-pbkdf 1.0.2 间接依赖 npm
which-module 2.0.1 间接依赖 npm
run-async 2.4.1 间接依赖 npm
symfony/console v6.3.4 间接依赖 composer
to-array 0.1.4 间接依赖 npm
tooltip-plugin 1.0.16 间接依赖 npm
mime-db 1.52.0 间接依赖 npm
request 2.88.2 间接依赖 npm
mimic-fn 2.1.0 间接依赖 npm
voku/anti-xss 4.1.42 间接依赖 composer
symfony/polyfill-uuid v1.28.0 间接依赖 composer
laravel/tinker v2.8.2 间接依赖 composer
get-caller-file 2.0.5 间接依赖 npm
doctrine/deprecations 1.1.2 间接依赖 composer
yeast 0.1.2 间接依赖 npm
forwarded 0.2.0 间接依赖 npm
laravel/ui v4.2.2 间接依赖 composer
os-tmpdir 1.0.2 间接依赖 npm
utils-merge 1.0.1 间接依赖 npm
has-symbols 1.0.3 间接依赖 npm
league/flysystem 3.17.0 间接依赖 composer
array-flatten 1.1.1 间接依赖 npm
psr/clock 1.0.0 间接依赖 composer
base64-arraybuffer 0.1.4 间接依赖 npm
egulias/email-validator 4.0.2 间接依赖 composer
nunomaduro/termwind v1.15.1 间接依赖 composer
alpinejs 3.13.1 间接依赖 npm
@types/range-parser 1.2.5 间接依赖 npm
media-typer 0.3.0 间接依赖 npm
component-inherit 0.0.3 间接依赖 npm
joypixels/emoji-toolkit 6.6.0 间接依赖 composer
aws4 1.12.0 间接依赖 npm
form-data 2.3.3 间接依赖 npm
illuminate/view 间接依赖 composer
type-fest 0.21.3 间接依赖 npm
league/commonmark 2.4.1 间接依赖 composer
mute-stream 0.0.8 间接依赖 npm
vstelmakh/url-highlight v3.0.2 间接依赖 composer
is-typedarray 1.0.0 间接依赖 npm
symfony/dom-crawler v6.3.4 间接依赖 composer
external-editor 3.1.0 间接依赖 npm
iconv-lite 0.4.24 间接依赖 npm
camelcase 5.3.1 间接依赖 npm
fruitcake/php-cors v1.2.0 间接依赖 composer
qs 6.5.3 间接依赖 npm
symfony/event-dispatcher v6.3.2 间接依赖 composer
spatie/laravel-backup 8.3.4 间接依赖 composer
hdvinnie/laravel-security-headers v2.0.0 间接依赖 composer
json-stringify-safe 5.0.1 间接依赖 npm
league/config v1.2.0 间接依赖 composer
tijsverkoyen/css-to-inline-styles 2.2.6 间接依赖 composer
proxy-addr 2.0.7 间接依赖 npm
base64id 2.0.0 间接依赖 npm
inherits 2.0.4 间接依赖 npm
symfony/routing v6.3.5 间接依赖 composer
has-cors 1.1.0 间接依赖 npm
dayjs 1.11.10 间接依赖 npm
masterminds/html5 2.8.1 间接依赖 composer
pusher-js 7.6.0 间接依赖 npm
chalk 4.1.2 间接依赖 npm
safe-buffer 5.2.1 间接依赖 npm
gabrielelana/byte-units 0.5.0 间接依赖 composer
accepts 1.3.8 间接依赖 npm
parseuri 0.0.6 间接依赖 npm
inquirer 7.3.3 间接依赖 npm
spatie/macroable 2.0.0 间接依赖 composer
component-emitter 1.3.0 间接依赖 npm
cookie 0.5.0 间接依赖 npm
component-bind 1.0.0 间接依赖 npm
jsbn 0.1.1 间接依赖 npm
nesbot/carbon 2.71.0 间接依赖 composer
symfony/polyfill-mbstring v1.28.0 间接依赖 composer
illuminate/support 间接依赖 composer
doctrine/event-manager 2.0.0 间接依赖 composer
wrap-ansi 6.2.0 间接依赖 npm
set-blocking 2.0.0 间接依赖 npm
extend 3.0.2 间接依赖 npm
express 4.18.2 间接依赖 npm
socket.io-client 2.5.0 间接依赖 npm
p-locate 4.1.0 间接依赖 npm
cli-cursor 3.1.0 间接依赖 npm
parseurl 1.3.3 间接依赖 npm
lodash.defaults 4.2.0 间接依赖 npm
ecc-jsbn 0.1.2 间接依赖 npm
on-finished 2.4.1 间接依赖 npm
mime 1.6.0 间接依赖 npm
isarray 2.0.1 间接依赖 npm
statuses 2.0.1 间接依赖 npm
indexof 0.0.1 间接依赖 npm
extsprintf 1.3.0 间接依赖 npm
caseless 0.12.0 间接依赖 npm
has 1.0.4 间接依赖 npm
raw-body 2.5.1 间接依赖 npm
symfony/var-dumper v6.3.5 间接依赖 composer
@vue/reactivity 3.1.5 间接依赖 npm
livewire/livewire v2.12.6 间接依赖 composer
getpass 0.1.7 间接依赖 npm
vary 1.1.2 间接依赖 npm
http-signature 1.2.0 间接依赖 npm
verror 1.10.0 间接依赖 npm
socket.io-parser 3.4.3 间接依赖 npm
symfony/polyfill-php72 v1.28.0 间接依赖 composer
merge-descriptors 1.0.1 间接依赖 npm
webmozart/assert 1.11.0 间接依赖 composer
brick/math 0.11.0 间接依赖 composer
@types/express-serve-static-core 4.17.28 间接依赖 npm
symfony/deprecation-contracts v3.3.0 间接依赖 composer
has-binary2 1.0.3 间接依赖 npm
redis-errors 1.2.0 间接依赖 npm
guzzlehttp/psr7 2.6.1 间接依赖 composer
uri-js 4.4.1 间接依赖 npm
ramsey/collection 2.0.0 间接依赖 composer
component-emitter 1.2.1 间接依赖 npm
league/mime-type-detection 1.13.0 间接依赖 composer
(0)
上一篇 2023年10月29日
下一篇 2023年10月29日

相关推荐

  • gsgundam/jQuery.resBg 软件分析报告

    基础信息 项目名称:gsgundam/jQuery.resBg 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718381501880074240/1718381502186258432 此报告由Murphyse…

    软件分析 2023年10月29日
    0
  • GloBee-Official/payment-api-php 软件分析报告

    基础信息 项目名称:GloBee-Official/payment-api-php 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721227760310943744/1728205820977434624 此报…

    软件分析 2023年11月25日
    0
  • kevinzhow/Waver 软件分析报告

    基础信息 项目名称:kevinzhow/Waver 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721336722544427008/1724434075047387136 此报告由Murphysec提供 漏洞…

    软件分析 2023年11月14日
    0
  • hpcaitech/ColossalAI 软件分析报告

    基础信息 项目名称:hpcaitech/ColossalAI 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718667467391025152/1718667467428773888 此报告由Murphysec…

    软件分析 2023年10月30日
    0
  • cmlenz/jquery-iframe-transport 软件分析报告

    基础信息 项目名称:cmlenz/jquery-iframe-transport 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716753226392190976/1716753226463494144 此报告…

    软件分析 2023年10月24日
    0