基础信息
项目名称:XiaoMi/Gaea
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1719948866387492864/1719948867880665088
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
jwt-go 安全漏洞 | 授权检查缺失 | MPS-2020-13786 | CVE-2020-26160 | 高危 |
Gin-Gonic Gin 环境问题漏洞 | HTTP请求走私 | MPS-2021-5932 | CVE-2020-28483 | 高危 |
Gin-Gonic Gin 输入验证错误漏洞 | 输入验证不恰当 | MPS-2023-5119 | CVE-2023-26125 | 高危 |
Gin 安全漏洞 | 下载代码缺少完整性检查 | MPS-2023-9711 | CVE-2023-29401 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
github.com/dgrijalva/jwt-go | v3.2.0+incompatible | 4.0.0-preview1 | 间接依赖 | 建议修复 |
github.com/gin-gonic/gin | v1.7.2 | 1.9.1 | 直接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 19 | 低 |
Apache-2.0 | 16 | 低 |
BSD-3-Clause | 8 | 低 |
BSD-2-Clause | 5 | 低 |
ISC | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
github.com/xiang90/probing | v0.0.0-20190116061207-43a291ad63a2 | 间接依赖 | go |
github.com/golang-jwt/jwt | v3.2.1+incompatible | 间接依赖 | go |
github.com/prometheus/client_golang | v0.9.2 | 直接依赖 | go |
github.com/coreos/etcd | v3.3.13+incompatible | 直接依赖 | go |
google.golang.org/protobuf | v1.27.1 | 间接依赖 | go |
github.com/gogo/protobuf | v1.2.1 | 间接依赖 | go |
github.com/grpc-ecosystem/go-grpc-middleware | v1.0.0 | 间接依赖 | go |
github.com/sirupsen/logrus | v1.4.2 | 间接依赖 | go |
github.com/gin-gonic/gin | v1.7.2 | 直接依赖 | go |
github.com/coreos/go-systemd | v0.0.0-20181012123002-c6f51f82210d | 间接依赖 | go |
github.com/emirpasic/gods | v1.12.0 | 直接依赖 | go |
github.com/golang/protobuf | v1.5.2 | 间接依赖 | go |
github.com/tmc/grpc-websocket-proxy | v0.0.0-20170815181823-89b8d40f7ca8 | 间接依赖 | go |
go.etcd.io/bbolt | v1.3.2 | 间接依赖 | go |
github.com/coreos/pkg | v0.0.0-20160727233714-3ac0863d7acf | 间接依赖 | go |
gopkg.in/yaml.v2 | v2.4.0 | 间接依赖 | go |
github.com/remyoudompheng/bigfft | v0.0.0-20190321074620-2f0d2b0e0001 | 间接依赖 | go |
github.com/gorilla/websocket | v1.4.2 | 间接依赖 | go |
github.com/google/btree | v1.0.0 | 间接依赖 | go |
github.com/mattn/go-isatty | v0.0.13 | 间接依赖 | go |
golang.org/x/time | v0.0.0-20181108054448-85acf8d2951c | 间接依赖 | go |
go.uber.org/zap | v1.10.0 | 间接依赖 | go |
gopkg.in/ini.v1 | v1.42.0 | 直接依赖 | go |
github.com/pingcap/check | v0.0.0-20190102082844-67f458068fc8 | 直接依赖 | go |
google.golang.org/grpc | v1.21.0 | 间接依赖 | go |
github.com/go-ini/ini | v1.42.0 | 直接依赖 | go |
github.com/go-playground/validator/v10 | v10.8.0 | 间接依赖 | go |
github.com/jonboulle/clockwork | v0.1.0 | 间接依赖 | go |
github.com/cznic/mathutil | v0.0.0-20181122101859-297441e03548 | 直接依赖 | go |
github.com/stretchr/testify | v1.6.1 | 直接依赖 | go |
github.com/pingcap/errors | v0.11.1 | 直接依赖 | go |
github.com/gin-contrib/gzip | v0.0.1 | 直接依赖 | go |
github.com/grpc-ecosystem/grpc-gateway | v1.9.0 | 间接依赖 | go |
github.com/soheilhy/cmux | v0.1.4 | 间接依赖 | go |
github.com/coreos/go-semver | v0.2.0 | 间接依赖 | go |
github.com/golang/mock | v1.1.1 | 直接依赖 | go |
github.com/golang/groupcache | v0.0.0-20160516000752-02826c3e7903 | 间接依赖 | go |
github.com/dgrijalva/jwt-go | v3.2.0+incompatible | 间接依赖 | go |
github.com/smartystreets/goconvey | v0.0.0-20190222223459-a17d461953aa | 间接依赖 | go |
github.com/ugorji/go | v1.2.6 | 间接依赖 | go |
github.com/json-iterator/go | v1.1.11 | 间接依赖 | go |
github.com/grpc-ecosystem/go-grpc-prometheus | v1.2.0 | 间接依赖 | go |
github.com/pkg/errors | v0.8.1 | 间接依赖 | go |
github.com/coreos/bbolt | v1.3.2 | 间接依赖 | go |
go.uber.org/atomic | v1.4.0 | 间接依赖 | go |
go.uber.org/multierr | v1.1.0 | 间接依赖 | go |
github.com/pingcap/tipb | v0.0.0-20190226124958-833c2ffd2fe7 | 直接依赖 | go |