iflytek/aiges 软件分析报告

基础信息

项目名称:iflytek/aiges

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1719344780949454848/1719344781385662464

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
低危
Gin 安全漏洞 下载代码缺少完整性检查 MPS-2023-9711 CVE-2023-29401 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
github.com/gin-gonic/gin v1.9.0 1.9.1 直接依赖 可选修复
golang.org/x/net v0.7.0 0.17.0 直接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 44
Apache-2.0 25
BSD-3-Clause 19
BSD-2-Clause 3
MPL-2.0 4

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/tidwall/match v1.1.1 间接依赖 go
github.com/KyleBanks/depth v1.2.1 间接依赖 go
google.golang.org/genproto v0.0.0-20200825200019-8632dd797987 间接依赖 go
github.com/leodido/go-urn v1.2.1 间接依赖 go
github.com/xfyun/lbClientPb v0.0.0-20220331063509-ef4be7a68a22 间接依赖 go
github.com/klauspost/cpuid/v2 v2.0.9 间接依赖 go
github.com/xfyun/flume v0.0.0-20220331061655-38a49b5af7f9 间接依赖 go
github.com/go-playground/validator/v10 v10.11.2 间接依赖 go
github.com/cooleric/go-zookeeper v0.0.0-20180110082822-77d7ab8968c9 间接依赖 go
github.com/mitchellh/go-ps v1.0.0 间接依赖 go
github.com/xfyun/lumberjack-ccr v0.0.0-20211213032130-b21985544bd2 间接依赖 go
github.com/prometheus/procfs v0.6.0 间接依赖 go
github.com/VividCortex/ewma v1.1.1 间接依赖 go
golang.org/x/arch v0.0.0-20210923205945-b76863e36670 间接依赖 go
github.com/shirou/gopsutil/v3 v3.21.7 间接依赖 go
github.com/pyroscope-io/dotnetdiag v1.2.1 间接依赖 go
github.com/tklauser/numcpus v0.2.3 间接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
libpthread.so.0 间接依赖
github.com/bytedance/sonic v1.8.0 间接依赖 go
github.com/BurntSushi/toml v0.4.1 间接依赖 go
libbz2.so.1.0 间接依赖
health_pb2_grpc 间接依赖 pip
github.com/oliveagle/jsonpath v0.0.0-20180606110733-2e52cf6e6852 直接依赖 go
golang.org/x/sys v0.5.0 间接依赖 go
github.com/gorilla/websocket v1.5.0 直接依赖 go
github.com/shirou/gopsutil v3.21.4+incompatible 间接依赖 go
github.com/go-openapi/swag v0.19.15 间接依赖 go
go.uber.org/zap v1.21.0 间接依赖 go
golang.org/x/net v0.7.0 直接依赖 go
github.com/Microsoft/go-winio v0.5.0 间接依赖 go
github.com/xfyun/thrift v0.0.0-20210423095925-0ef93ee2c654 间接依赖 go
github.com/xfyun/finder-go v0.0.0-20220331051723-e16091b3b281 间接依赖 go
github.com/seeadoog/jsonschema v1.1.0 直接依赖 go
github.com/minio/blake2b-simd v0.0.0-20160723061019-3f5f724cb5b1 间接依赖 go
github.com/invopop/yaml v0.1.0 间接依赖 go
github.com/mitchellh/go-testing-interface v1.0.0 间接依赖 go
github.com/twitchyliquid64/golang-asm v0.15.1 间接依赖 go
github.com/prometheus/common v0.32.1 间接依赖 go
github.com/garyburd/redigo v1.6.3 间接依赖 go
github.com/getkin/kin-openapi v0.108.0 直接依赖 go
github.com/xfyun/redisgo v0.0.0-20220331072549-8b4cfc76e532 间接依赖 go
github.com/samuel/go-zookeeper v0.0.0-20201211165307-7117e9ea2414 间接依赖 go
libgcc_s.so.1 间接依赖
github.com/xfyun/sonar v0.0.0-20220331071109-0b7c3a371c9a 间接依赖 go
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac 间接依赖 go
github.com/go-openapi/jsonreference v0.19.6 间接依赖 go
github.com/fatih/color v1.10.0 间接依赖 go
golang.org/x/text v0.7.0 间接依赖 go
github.com/StackExchange/wmi v1.2.1 间接依赖 go
github.com/xfyun/uuid v0.0.0-20220331052528-3a275a5702d5 直接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 间接依赖 go
github.com/go-ole/go-ole v1.2.5 间接依赖 go
libdl.so.2 间接依赖
github.com/alecthomas/template v0.0.0-20190718012654-fb15b899a751 直接依赖 go
stathat.com/c/consistent v1.0.0 间接依赖 go
ld-linux-x86-64.so.2 间接依赖
github.com/mattn/go-colorable v0.1.8 间接依赖 go
github.com/aws/aws-sdk-go v1.44.28 直接依赖 go
github.com/json-iterator/go v1.1.12 直接依赖 go
github.com/prometheus/client_golang v1.11.0 间接依赖 go
golang.org/x/crypto v0.5.0 间接依赖 go
github.com/hashicorp/go-hclog v0.14.1 直接依赖 go
github.com/josharian/intern v1.0.0 间接依赖 go
github.com/mailru/easyjson v0.7.6 间接依赖 go
github.com/xfyun/flange v0.0.0-20220331071834-05b49d1403f6 间接依赖 go
github.com/swaggo/swag v1.8.7 直接依赖 go
github.com/pelletier/go-toml/v2 v2.0.6 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/pyroscope-io/pyroscope v0.18.0 直接依赖 go
github.com/go-openapi/spec v0.20.4 间接依赖 go
github.com/tklauser/go-sysconf v0.3.7 间接依赖 go
github.com/golang/protobuf v1.5.2 直接依赖 go
github.com/mattn/go-isatty v0.0.17 间接依赖 go
github.com/go-playground/universal-translator v0.18.1 间接依赖 go
libIceUtil.so.34 间接依赖
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
librt.so.1 间接依赖
google.golang.org/grpc v1.32.0 直接依赖 go
github.com/ugorji/go/codec v1.2.9 间接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
go.uber.org/multierr v1.6.0 间接依赖 go
github.com/tidwall/pretty v1.2.0 间接依赖 go
github.com/valyala/bytebufferpool v1.0.0 间接依赖 go
github.com/chenzhuoyu/base64x v0.0.0-20221115062448-fe3a3abad311 间接依赖 go
github.com/hashicorp/yamux v0.0.0-20180604194846-3520598351bb 间接依赖 go
github.com/hashicorp/go-plugin v1.4.5 直接依赖 go
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 间接依赖 go
github.com/goccy/go-json v0.10.0 间接依赖 go
github.com/go-redis/redis v6.15.9+incompatible 直接依赖 go
github.com/go-playground/locales v0.14.1 间接依赖 go
github.com/streadway/amqp v1.0.0 直接依赖 go
github.com/xfyun/xsf v0.0.0-20220402010628-6507dace16c0 直接依赖 go
go.uber.org/atomic v1.7.0 间接依赖 go
google.golang.org/protobuf v1.28.1 直接依赖 go
github.com/cespare/xxhash/v2 v2.1.2 间接依赖 go
libc.so.6 间接依赖
github.com/gin-gonic/gin v1.9.0 直接依赖 go
github.com/xfyun/lb_client v0.0.0-20220331073237-7f0320449c11 间接依赖 go
golang.org/x/tools v0.1.12 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.5 间接依赖 go
github.com/gin-contrib/sse v0.1.0 间接依赖 go
github.com/tidwall/gjson v1.14.0 间接依赖 go
github.com/prometheus/client_model v0.2.0 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
health_pb2 间接依赖 pip
github.com/cihub/seelog v0.0.0-20170130134532-f561c5e57575 间接依赖 go
libstdc++.so.6 间接依赖
github.com/swaggo/gin-swagger v1.5.3 直接依赖 go
libm.so.6 间接依赖
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
github.com/PuerkitoBio/purell v1.1.1 间接依赖 go
github.com/mohae/deepcopy v0.0.0-20170929034955-c48cc78d4826 间接依赖 go
github.com/oklog/run v1.0.0 间接依赖 go
(0)
上一篇 2023年10月31日
下一篇 2023年10月31日

相关推荐

  • easymock/easymock 软件分析报告

    基础信息 项目名称:easymock/easymock 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721153949934882816/1722875471869730816 此报告由Murphysec提供 …

    软件分析 2023年11月10日
    0
  • GetBlimp/built-with-ember 软件分析报告

    基础信息 项目名称:GetBlimp/built-with-ember 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718083765191622656/1718083765338423296 此报告由Murp…

    软件分析 2023年10月28日
    0
  • JetBrains/xodus 软件分析报告

    基础信息 项目名称:JetBrains/xodus 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721305871253274624/1728447845597401088 此报告由Murphysec提供 漏洞…

    软件分析 2023年11月26日
    0
  • kuberhealthy/kuberhealthy 软件分析报告

    基础信息 项目名称:kuberhealthy/kuberhealthy 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721350410030895104/1724543557707976704 此报告由Murp…

    软件分析 2023年11月15日
    0
  • elliotchance/c2go 软件分析报告

    基础信息 项目名称:elliotchance/c2go 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1717431700556480512/1717431701177237504 此报告由Murphysec提供 …

    软件分析 2023年10月26日
    0