YunaiV/onemall 软件分析报告

基础信息

项目名称:YunaiV/onemall

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1720280441552277504/1720280448435130368

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Spring Framework 反序列化 MPS-2020-0057 CVE-2016-1000027 严重
dom4j SaxReader函数存在 XXE 漏洞 XXE MPS-2020-6967 CVE-2020-10683 严重
Apache Commons Compress 安存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10550 CVE-2021-35517 高危
Apache Commons Compress 存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10551 CVE-2021-35516 高危
Apache Commons Compress 存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10564 CVE-2021-36090 高危
Apache Commons Compress 无限循环漏洞 不可达退出条件的循环(无限循环) MPS-2021-10565 CVE-2021-35515 高危
AviatorScript 存在注入漏洞 注入 MPS-2021-32682 CVE-2021-41862 严重
snakeYAML 拒绝服务 MPS-2022-5144 CVE-2022-25857 高危
Bouncy Castle 密码学问题 MPS-2022-54305 中危
snakeYAML 栈缓冲区溢出 MPS-2022-56040 CVE-2022-38751 中危
snakeYAML 栈缓冲区溢出 MPS-2022-56041 CVE-2022-38752 低危
snakeYAML 栈缓冲区溢出 MPS-2022-56051 CVE-2022-38750 中危
snakeYAML 拒绝服务 MPS-2022-56081 CVE-2022-38749 中危
Apache POI 不加限制或调节的资源分配 MPS-2022-5663 CVE-2022-26336 中危
Jettison 拒绝服务 MPS-2022-57067 CVE-2022-40150 高危
Jettison 越界写入 MPS-2022-57068 CVE-2022-40149 高危
xuxueli xxl-job 存在命令注入漏洞 命令注入 MPS-2022-57270 CVE-2022-40929 严重
SnakeYAML 栈缓冲区溢出 MPS-2022-58478 CVE-2022-41854 中危
FasterXML jackson-databind 小于2.14.0-rc1拒绝服务漏洞 拒绝服务 MPS-2022-58653 CVE-2022-42003 中危
Jettison 越界写入 MPS-2022-64973 CVE-2022-45685 高危
H2 数据库明文密码问题 未授权敏感信息泄露 MPS-2022-65204 CVE-2022-45868 高危
snakeYAML 反序列化 MPS-2022-9425 CVE-2022-1471 高危
Apache Commons FileUpload 不加限制或调节的资源分配 MPS-2023-3553 CVE-2023-24998 中危
XXL-JOB 跨站请求伪造漏洞 CSRF MPS-2023-3818 CVE-2023-0674 中危
xxl-job 存在存储型XSS漏洞 XSS MPS-2023-5196 中危
Jettison 安全漏洞 未经控制的递归 MPS-2023-8270 CVE-2023-1436 高危
Apache Tomcat http请求走私漏洞 输入验证不恰当 MPS-b5of-dwyh CVE-2023-45648 中危
Hot Rod 安全漏洞 证书验证不恰当 MPS-b7oj-adm3 CVE-2023-4586 高危
Apache Tomcat 安全漏洞 清理环节不完整 MPS-hz9y-jtfe CVE-2023-42795 中危
Bouncy Castle 信任管理问题漏洞 证书验证不恰当 MPS-i6w7-d48e CVE-2023-33201 中危
Apache Tomcat 安全漏洞 清理环节不完整 MPS-l8rt-k2nh CVE-2023-42794 高危
基于 Thymeleaf 沙箱逃逸的 Spring Boot Admin 远程代码执行漏洞 代码注入 MPS-p6bo-i7nw CVE-2023-38286 严重
dom4j 安全漏洞 XPath盲注 MPS-qmvc-a2ln CVE-2023-45960 高危
Snappy 安全漏洞 不加限制或调节的资源分配 MPS-s7wb-p03z CVE-2023-43642 高危
Redisson 代码问题漏洞 反序列化 MPS-t5lb-2zr9 CVE-2023-42809 高危
【存在争议】FasterXML jackson-databind 代码问题漏洞 不加限制或调节的资源分配 MPS-z1bx-p8y2 CVE-2023-35116 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
de.codecentric:spring-boot-admin-server 2.7.10 3.1.2 间接依赖 强烈建议修复
org.apache.tomcat.embed:tomcat-embed-core 9.0.80 9.0.81 间接依赖 建议修复
org.yaml:snakeyaml 1.30 2.0 间接依赖 建议修复
com.xuxueli:xxl-job-core 2.3.1 直接依赖 建议修复
com.fasterxml.jackson.core:jackson-databind 2.13.5 直接依赖 建议修复
org.codehaus.jettison:jettison 1.1 1.5.4 间接依赖 建议修复
dom4j:dom4j 1.6.1 间接依赖 建议修复
commons-fileupload:commons-fileupload 1.4 1.5 间接依赖 建议修复
com.googlecode.aviator:aviator 5.2.6 间接依赖 建议修复
org.springframework:spring-web 5.3.30 6.0.0 直接依赖 建议修复
org.apache.commons:commons-compress 1.19 1.21 间接依赖 建议修复
org.redisson:redisson 3.18.0 3.22.0 间接依赖 可选修复
org.bouncycastle:bcprov-jdk15on 1.68 间接依赖 可选修复
org.bouncycastle:bcprov-jdk15on 1.69 间接依赖 可选修复
org.bouncycastle:bcprov-jdk15on 1.70 间接依赖 可选修复
org.xerial.snappy:snappy-java 1.1.10.1 1.1.10.4 间接依赖 可选修复
org.apache.poi:poi-scratchpad 4.1.2 5.2.1 间接依赖 可选修复
com.h2database:h2 2.1.214 直接依赖 可选修复
org.dom4j:dom4j 2.1.3 间接依赖 可选修复
io.netty:netty-handler 4.1.97.Final 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 385
自定义许可证 33
CDDL-1.1 1
MIT 13
EPL-2.0 12
GPL-3.0 1
BSD-2-Clause 5
MPL-2.0 2
EPL-1.0 3
BSD-3-Clause 1
MIT-0 1
WTFPL 1
LGPL-2.1 2
LGPL-3.0 1
MPL-1.1 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
org.flowable:flowable-form-api 6.8.0 间接依赖 maven
com.github.yulichang:mybatis-plus-join-core 1.4.6 间接依赖 maven
com.alibaba:druid 1.2.19 间接依赖 maven
org.apache.tomcat.embed:tomcat-embed-el 9.0.80 间接依赖 maven
com.github.yulichang:mybatis-plus-join-boot-starter 1.4.6 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-sms 1.8.3-snapshot 直接依赖 maven
org.flowable:flowable-event-registry-model 6.8.0 间接依赖 maven
org.apache.commons:commons-pool2 2.11.1 间接依赖 maven
org.jeecgframework.jimureport:jimureport-spring-boot-starter 1.6.1 直接依赖 maven
org.flowable:flowable-spring-boot-starter-process 6.8.0 直接依赖 maven
org.bouncycastle:bcprov-jdk15on 1.69 间接依赖 maven
org.jeecgframework:autopoi 1.4.6 间接依赖 maven
org.flowable:flowable-spring-boot-autoconfigure 6.8.0 间接依赖 maven
com.github.binarywang:weixin-java-mp 4.5.0 间接依赖 maven
org.mapstruct:mapstruct 1.5.5.Final 直接依赖 maven
javax.xml.bind:jaxb-api 2.3.1 间接依赖 maven
cn.iocoder.cloud:yudao-module-system-api 1.8.3-snapshot 直接依赖 maven
com.fasterxml.jackson.core:jackson-databind 2.13.5 直接依赖 maven
org.redisson:redisson-spring-data-27 3.18.0 间接依赖 maven
org.flowable:flowable-event-registry-spring 6.8.0 间接依赖 maven
org.thymeleaf.extras:thymeleaf-extras-java8time 3.0.4.RELEASE 间接依赖 maven
com.xingyuv:simple-http 1.0.5 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-security 1.8.3-snapshot 直接依赖 maven
com.baomidou:mybatis-plus-annotation 3.5.3.2 间接依赖 maven
net.minidev:json-smart 2.4.11 间接依赖 maven
com.sun.istack:istack-commons-runtime 3.0.12 间接依赖 maven
org.springframework:spring-webmvc 5.3.30 间接依赖 maven
org.springframework.boot:spring-boot-starter-jdbc 2.7.16 间接依赖 maven
io.github.resilience4j:resilience4j-circularbuffer 1.7.0 间接依赖 maven
org.apache.rocketmq:rocketmq-srvutil 4.9.4 间接依赖 maven
org.apache.httpcomponents:httpcore 4.4.16 间接依赖 maven
org.springframework.cloud:spring-cloud-starter 3.1.5 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-dict 1.8.3-snapshot 直接依赖 maven
org.springdoc:springdoc-openapi-webmvc-core 1.6.15 间接依赖 maven
org.springframework:spring-context-support 5.3.30 间接依赖 maven
org.slf4j:slf4j-api 1.7.36 直接依赖 maven
org.springframework.boot:spring-boot-starter-web 2.7.16 直接依赖 maven
io.netty:netty-codec-mqtt 4.1.97.Final 间接依赖 maven
javax.activation:activation 1.1 间接依赖 maven
commons-io:commons-io 2.11.0 间接依赖 maven
com.sun.mail:jakarta.mail 1.6.7 间接依赖 maven
com.github.fppt:jedis-mock 1.0.7 直接依赖 maven
com.github.jsqlparser:jsqlparser 4.4 间接依赖 maven
com.xuxueli:xxl-job-core 2.3.1 直接依赖 maven
com.squareup.okhttp3:logging-interceptor 4.9.3 间接依赖 maven
io.netty:netty-codec-dns 4.1.97.Final 间接依赖 maven
org.apache.commons:commons-compress 1.19 间接依赖 maven
io.netty:netty-handler 4.1.97.Final 间接依赖 maven
org.junit.platform:junit-platform-commons 1.8.2 间接依赖 maven
org.thymeleaf:thymeleaf 3.0.15.RELEASE 间接依赖 maven
io.netty:netty-codec 4.1.97.Final 间接依赖 maven
org.springframework.cloud:spring-cloud-commons 3.1.5 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib 1.6.21 间接依赖 maven
io.github.resilience4j:resilience4j-bulkhead 1.7.0 间接依赖 maven
org.springframework.cloud:spring-cloud-starter-bootstrap 3.1.5 直接依赖 maven
org.springframework.cloud:spring-cloud-stream 3.2.6 间接依赖 maven
cn.iocoder.cloud:yudao-module-member-api 1.8.3-snapshot 直接依赖 maven
com.aliyun:aliyun-java-sdk-kms 2.11.0 间接依赖 maven
io.netty:netty-buffer 4.1.97.Final 间接依赖 maven
org.bouncycastle:bcprov-jdk18on 1.74 间接依赖 maven
jakarta.annotation:jakarta.annotation-api 1.3.5 间接依赖 maven
cn.iocoder.cloud:yudao-module-report-api 1.8.3-snapshot 直接依赖 maven
org.springframework.data:spring-data-commons 2.7.16 间接依赖 maven
org.flowable:flowable-cmmn-api 6.8.0 间接依赖 maven
org.springframework:spring-jdbc 5.3.30 间接依赖 maven
org.apache.skywalking:apm-toolkit-logback-1.x 8.12.0 直接依赖 maven
org.hdrhistogram:HdrHistogram 2.1.12 间接依赖 maven
com.microsoft.sqlserver:mssql-jdbc 10.2.3.jre8 直接依赖 maven
com.google.guava:listenablefuture 9999.0-empty-to-avoid-conflict-with-guava 间接依赖 maven
org.springframework.cloud:spring-cloud-function-context 3.2.8 间接依赖 maven
dom4j:dom4j 1.6.1 间接依赖 maven
commons-logging:commons-logging 1.1.1 间接依赖 maven
com.zaxxer:HikariCP 4.0.3 间接依赖 maven
org.ehcache:ehcache 3.10.8 间接依赖 maven
org.springframework.boot:spring-boot-starter-reactor-netty 2.7.16 间接依赖 maven
io.netty:netty-codec-http 4.1.97.Final 间接依赖 maven
io.netty:netty-transport-native-kqueue 4.1.97.Final 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-mq 1.8.3-snapshot 直接依赖 maven
com.github.jsqlparser:jsqlparser 4.6 间接依赖 maven
xmlpull:xmlpull 1.1.3.1 间接依赖 maven
cn.iocoder.cloud:yudao-module-promotion-api 1.8.3-snapshot 直接依赖 maven
io.github.openfeign:feign-slf4j 11.10 间接依赖 maven
com.aliyun:aliyun-java-sdk-core 4.6.4 直接依赖 maven
de.codecentric:spring-boot-admin-server-ui 2.7.10 间接依赖 maven
redis.clients:jedis 3.8.0 间接依赖 maven
org.mockito:mockito-junit-jupiter 4.5.1 间接依赖 maven
org.apache.tomcat.embed:tomcat-embed-core 9.0.80 间接依赖 maven
io.vavr:vavr-match 0.10.2 间接依赖 maven
io.netty:netty-codec-http2 4.1.97.Final 间接依赖 maven
org.flowable:flowable-job-service 6.8.0 间接依赖 maven
org.mybatis:mybatis-spring 2.1.1 间接依赖 maven
org.springframework:spring-test 5.3.30 间接依赖 maven
org.bouncycastle:bcprov-jdk15on 1.68 间接依赖 maven
org.junit.jupiter:junit-jupiter-params 5.8.2 间接依赖 maven
io.netty:netty-transport-rxtx 4.1.97.Final 间接依赖 maven
com.alibaba.nacos:nacos-client 2.0.4 间接依赖 maven
cn.iocoder.cloud:yudao-module-product-api 1.8.3-snapshot 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-job 1.8.3-snapshot 直接依赖 maven
org.aspectj:aspectjrt 1.9.7 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-pay 1.8.3-snapshot 直接依赖 maven
org.mockito:mockito-inline 4.11.0 直接依赖 maven
org.aspectj:aspectjweaver 1.9.7 间接依赖 maven
org.freemarker:freemarker 2.3.32 间接依赖 maven
org.springframework.boot:spring-boot-autoconfigure 2.7.16 间接依赖 maven
io.prometheus:simpleclient 0.15.0 间接依赖 maven
commons-fileupload:commons-fileupload 1.4 间接依赖 maven
org.flowable:flowable-engine-common-api 6.8.0 间接依赖 maven
org.apache.skywalking:apm-toolkit-trace 8.12.0 直接依赖 maven
org.jodd:jodd-core 5.1.6 间接依赖 maven
org.springframework:spring-orm 5.3.30 间接依赖 maven
io.netty:netty-handler-proxy 4.1.97.Final 间接依赖 maven
com.baomidou:mybatis-plus 3.5.3.2 间接依赖 maven
org.springframework.cloud:spring-cloud-gateway-server 3.1.4 间接依赖 maven
org.flowable:flowable-engine-common 6.8.0 间接依赖 maven
com.vaadin.external.google:android-json 0.0.20131108.vaadin1 间接依赖 maven
jakarta.xml.bind:jakarta.xml.bind-api 2.3.3 间接依赖 maven
org.springframework:spring-jcl 5.3.30 间接依赖 maven
org.apache.httpcomponents:httpclient 4.5.14 间接依赖 maven
jakarta.validation:jakarta.validation-api 2.0.2 直接依赖 maven
org.flowable:flowable-variable-service-api 6.8.0 间接依赖 maven
io.github.resilience4j:resilience4j-framework-common 1.7.0 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-redis 1.8.3-snapshot 直接依赖 maven
com.aliyun.oss:aliyun-sdk-oss 3.11.2 间接依赖 maven
org.flowable:flowable-eventsubscription-service-api 6.8.0 间接依赖 maven
org.apache.commons:commons-csv 1.8 间接依赖 maven
xml-apis:xml-apis 1.4.01 间接依赖 maven
org.flowable:flowable-entitylink-service 6.8.0 间接依赖 maven
org.bouncycastle:bcutil-jdk15on 1.69 间接依赖 maven
io.opentracing:opentracing-api 0.33.0 间接依赖 maven
com.dameng:DmJdbcDriver18 8.1.2.141 直接依赖 maven
org.hibernate.validator:hibernate-validator 6.2.5.Final 间接依赖 maven
io.projectreactor.netty:reactor-netty-core 1.0.36 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-flowable 1.8.3-snapshot 直接依赖 maven
org.springframework.boot:spring-boot-actuator 2.7.16 间接依赖 maven
commons-cli:commons-cli 1.2 间接依赖 maven
io.netty:netty-codec-redis 4.1.97.Final 间接依赖 maven
org.attoparser:attoparser 2.0.5.RELEASE 间接依赖 maven
org.flowable:flowable-bpmn-layout 6.8.0 间接依赖 maven
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.13.5 直接依赖 maven
com.squareup.okhttp3:okhttp 4.11.0 间接依赖 maven
org.glassfish.jaxb:txw2 2.3.8 间接依赖 maven
io.github.openfeign.form:feign-form-spring 3.8.0 间接依赖 maven
io.opentracing:opentracing-util 0.33.0 直接依赖 maven
com.baomidou:dynamic-datasource-spring-boot-starter 3.6.1 直接依赖 maven
com.fasterxml.jackson.module:jackson-module-parameter-names 2.13.5 间接依赖 maven
org.springframework.boot:spring-boot 2.7.16 间接依赖 maven
org.slf4j:jcl-over-slf4j 1.7.36 间接依赖 maven
org.jodd:jodd-bean 5.1.6 间接依赖 maven
org.flowable:flowable-event-registry-api 6.8.0 间接依赖 maven
org.apache.xmlbeans:xmlbeans 3.1.0 间接依赖 maven
com.github.binarywang:weixin-java-pay 4.5.0 直接依赖 maven
org.objenesis:objenesis 3.2 间接依赖 maven
net.minidev:accessors-smart 2.4.11 间接依赖 maven
org.jeecgframework:minidao-pe 1.9.2 间接依赖 maven
org.flowable:flowable-task-service-api 6.8.0 间接依赖 maven
com.mysql:mysql-connector-j 8.0.33 直接依赖 maven
org.apache.tomcat.embed:tomcat-embed-websocket 9.0.80 间接依赖 maven
org.springframework.boot:spring-boot-starter 2.7.16 直接依赖 maven
com.google.j2objc:j2objc-annotations 2.8 间接依赖 maven
org.springframework.boot:spring-boot-starter-json 2.7.16 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-operatelog 1.8.3-snapshot 直接依赖 maven
org.jboss.logging:jboss-logging 3.4.3.Final 间接依赖 maven
com.baomidou:mybatis-plus-boot-starter 3.5.3.2 直接依赖 maven
com.google.guava:failureaccess 1.0.1 间接依赖 maven
org.apache.poi:poi-scratchpad 4.1.2 间接依赖 maven
org.jsoup:jsoup 1.16.1 直接依赖 maven
com.xingyuv:captcha-plus 1.0.8 间接依赖 maven
com.google.errorprone:error_prone_annotations 2.18.0 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-tenant 1.8.3-snapshot 直接依赖 maven
org.apache.rocketmq:rocketmq-remoting 4.9.4 间接依赖 maven
org.flowable:flowable-http-common 6.8.0 间接依赖 maven
com.alibaba.cloud:spring-cloud-starter-stream-rocketmq 2021.0.4.0 直接依赖 maven
javax.annotation:javax.annotation-api 1.3.2 间接依赖 maven
org.springframework.boot:spring-boot-starter-test 2.7.16 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-error-code 1.8.3-snapshot 直接依赖 maven
com.github.yulichang:mybatis-plus-join-adapter-v3431 1.4.6 间接依赖 maven
io.prometheus:simpleclient_tracer_otel_agent 0.15.0 间接依赖 maven
org.liquibase:liquibase-core 4.9.1 间接依赖 maven
io.swagger.core.v3:swagger-annotations 2.2.8 间接依赖 maven
commons-beanutils:commons-beanutils 1.9.4 间接依赖 maven
org.apache.poi:ooxml-schemas 1.4 间接依赖 maven
javax.validation:validation-api 2.0.1.Final 间接依赖 maven
org.apache.httpcomponents:httpmime 4.5.14 间接依赖 maven
com.github.binarywang:weixin-java-miniapp 4.5.0 间接依赖 maven
org.jdom:jdom2 2.0.6.1 间接依赖 maven
org.thymeleaf:thymeleaf-spring5 3.0.15.RELEASE 间接依赖 maven
org.springframework.cloud:spring-cloud-starter-gateway 3.1.4 直接依赖 maven
io.netty:netty-common 4.1.97.Final 间接依赖 maven
org.flowable:flowable-task-service 6.8.0 间接依赖 maven
org.redisson:redisson-spring-boot-starter 3.18.0 直接依赖 maven
org.springframework.boot:spring-boot-starter-webflux 2.7.16 间接依赖 maven
com.zaxxer:SparseBitSet 1.2 间接依赖 maven
org.apache.commons:commons-collections4 4.4 间接依赖 maven
org.redisson:redisson 3.18.0 间接依赖 maven
org.springframework:spring-aop 5.3.30 间接依赖 maven
org.flowable:flowable-dmn-model 6.8.0 间接依赖 maven
org.mybatis:mybatis 3.5.10 间接依赖 maven
io.netty:netty-all 4.1.97.Final 间接依赖 maven
org.springframework:spring-tx 5.3.30 间接依赖 maven
org.springframework.retry:spring-retry 1.3.4 间接依赖 maven
io.netty:netty-resolver-dns-native-macos 4.1.97.Final 间接依赖 maven
commons-digester:commons-digester 2.1 间接依赖 maven
org.junit.jupiter:junit-jupiter-engine 5.8.2 间接依赖 maven
com.fasterxml.uuid:java-uuid-generator 3.3.0 间接依赖 maven
com.alibaba.cloud:spring-cloud-starter-alibaba-nacos-config 2021.0.4.0 直接依赖 maven
org.flowable:flowable-idm-engine 6.8.0 间接依赖 maven
org.springframework.boot:spring-boot-test-autoconfigure 2.7.16 间接依赖 maven
org.flowable:flowable-cmmn-model 6.8.0 间接依赖 maven
cn.iocoder.cloud:yudao-module-statistics-api 1.8.3-snapshot 直接依赖 maven
org.skyscreamer:jsonassert 1.5.1 间接依赖 maven
com.h2database:h2 2.1.214 直接依赖 maven
com.sun.mail:javax.mail 1.5.6 间接依赖 maven
org.apache.httpcomponents:httpcore-nio 4.4.16 间接依赖 maven
org.ini4j:ini4j 0.5.4 间接依赖 maven
com.fasterxml.jackson.core:jackson-core 2.13.5 直接依赖 maven
org.springframework.boot:spring-boot-starter-logging 2.7.16 间接依赖 maven
com.stoyanr:evictor 1.0.0 间接依赖 maven
com.google.zxing:core 3.2.1 间接依赖 maven
com.google.code.gson:gson 2.9.1 间接依赖 maven
org.junit.jupiter:junit-jupiter-api 5.8.2 间接依赖 maven
com.github.binarywang:wx-java-miniapp-spring-boot-starter 4.5.0 直接依赖 maven
com.baomidou:mybatis-plus-core 3.5.3.2 间接依赖 maven
org.springframework:spring-web 5.3.30 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-env 1.8.3-snapshot 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-excel 1.8.3-snapshot 直接依赖 maven
org.springframework.data:spring-data-redis 2.7.16 间接依赖 maven
commons-validator:commons-validator 1.7 间接依赖 maven
org.glassfish.jaxb:jaxb-runtime 2.3.8 间接依赖 maven
org.flowable:flowable-bpmn-converter 6.8.0 间接依赖 maven
org.springframework.cloud:spring-cloud-starter-openfeign 3.1.5 直接依赖 maven
io.github.x-stream:mxparser 1.2.2 间接依赖 maven
com.alipay.sdk:alipay-sdk-java 4.35.79.ALL 直接依赖 maven
org.springframework.boot:spring-boot-starter-thymeleaf 2.7.16 间接依赖 maven
org.mybatis:mybatis 3.5.13 间接依赖 maven
org.springframework:spring-messaging 5.3.30 间接依赖 maven
de.codecentric:spring-boot-admin-starter-server 2.7.10 直接依赖 maven
io.netty:netty-transport-classes-kqueue 4.1.97.Final 间接依赖 maven
io.prometheus:simpleclient_tracer_common 0.15.0 间接依赖 maven
io.opentracing:opentracing-noop 0.33.0 间接依赖 maven
org.springframework.data:spring-data-keyvalue 2.7.16 间接依赖 maven
org.apache.rocketmq:rocketmq-client 4.9.4 间接依赖 maven
xml-apis:xml-apis 1.0.b2 间接依赖 maven
io.netty:netty-transport-classes-epoll 4.1.97.Final 间接依赖 maven
io.micrometer:micrometer-registry-prometheus 1.9.15 直接依赖 maven
io.github.resilience4j:resilience4j-annotations 1.7.0 间接依赖 maven
com.thoughtworks.xstream:xstream 1.4.20 间接依赖 maven
com.alibaba:easyexcel-support 3.3.2 间接依赖 maven
com.alibaba:druid-spring-boot-starter 1.2.19 直接依赖 maven
xerces:xercesImpl 2.12.2 直接依赖 maven
uk.co.jemos.podam:podam 7.2.11.RELEASE 直接依赖 maven
com.xingyuv:spring-boot-starter-captcha-plus 1.0.8 直接依赖 maven
com.baomidou:mybatis-plus-extension 3.5.3.2 间接依赖 maven
org.apache.logging.log4j:log4j-to-slf4j 2.17.2 间接依赖 maven
io.netty:netty-transport-udt 4.1.97.Final 间接依赖 maven
com.xingyuv:justauth 1.0.5 间接依赖 maven
org.webjars:webjars-locator-core 0.50 间接依赖 maven
io.github.resilience4j:resilience4j-micrometer 1.7.0 间接依赖 maven
de.codecentric:spring-boot-admin-server-cloud 2.7.10 间接依赖 maven
org.springframework.cloud:spring-cloud-context 3.1.5 间接依赖 maven
net.jodah:typetools 0.6.2 间接依赖 maven
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 2.13.5 间接依赖 maven
com.alibaba:easyexcel 3.3.2 直接依赖 maven
io.github.openfeign.form:feign-form 3.8.0 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-jdk8 1.6.21 间接依赖 maven
org.bouncycastle:bcpkix-jdk15on 1.68 间接依赖 maven
org.springframework.cloud:spring-cloud-starter-loadbalancer 3.1.5 直接依赖 maven
org.springdoc:springdoc-openapi-common 1.6.15 间接依赖 maven
io.github.classgraph:classgraph 4.8.149 间接依赖 maven
com.baomidou:lock4j-core 2.2.3 间接依赖 maven
org.flowable:flowable-identitylink-service-api 6.8.0 间接依赖 maven
com.github.yulichang:mybatis-plus-join-adapter-v33x 1.4.6 间接依赖 maven
io.netty:netty-transport-native-unix-common 4.1.97.Final 间接依赖 maven
com.jcraft:jsch 0.1.55 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-monitor 1.8.3-snapshot 直接依赖 maven
jakarta.activation:jakarta.activation-api 1.2.2 间接依赖 maven
com.googlecode.aviator:aviator 5.2.6 间接依赖 maven
com.github.yulichang:mybatis-plus-join-adapter-base 1.4.6 间接依赖 maven
com.github.xiaoymin:knife4j-gateway-spring-boot-starter 4.3.0 直接依赖 maven
org.flowable:flowable-idm-engine-configurator 6.8.0 间接依赖 maven
org.lionsoul:ip2region 2.7.0 直接依赖 maven
org.springframework.security:spring-security-web 5.7.11 间接依赖 maven
com.tencentcloudapi:tencentcloud-sdk-java-sms 3.1.853 直接依赖 maven
org.jetbrains:annotations 13.0 间接依赖 maven
org.jboss.marshalling:jboss-marshalling-river 2.0.11.Final 间接依赖 maven
io.github.resilience4j:resilience4j-timelimiter 1.7.0 间接依赖 maven
org.springframework.boot:spring-boot-starter-tomcat 2.7.16 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-web 1.8.3-snapshot 直接依赖 maven
io.github.resilience4j:resilience4j-retry 1.7.0 间接依赖 maven
cn.iocoder.cloud:yudao-module-mp-api 1.8.3-snapshot 直接依赖 maven
org.reactivestreams:reactive-streams 1.0.4 间接依赖 maven
com.tencentcloudapi:tencentcloud-sdk-java-common 3.1.853 间接依赖 maven
org.apiguardian:apiguardian-api 1.1.2 间接依赖 maven
net.bytebuddy:byte-buddy-agent 1.12.23 间接依赖 maven
ch.qos.logback:logback-classic 1.2.12 间接依赖 maven
com.github.yulichang:mybatis-plus-join-annotation 1.4.6 间接依赖 maven
com.alibaba:transmittable-thread-local 2.14.2 直接依赖 maven
com.alibaba.spring:spring-context-support 1.0.11 间接依赖 maven
io.github.resilience4j:resilience4j-spring 1.7.0 间接依赖 maven
org.flowable:flowable-job-spring-service 6.8.0 间接依赖 maven
org.springframework.cloud:spring-cloud-openfeign-core 3.1.5 间接依赖 maven
org.springframework.boot:spring-boot-starter-actuator 2.7.16 间接依赖 maven
com.aliyun:aliyun-java-sdk-ram 3.1.0 间接依赖 maven
joda-time:joda-time 2.10.13 间接依赖 maven
org.apache.httpcomponents:httpasyncclient 4.1.5 间接依赖 maven
org.springframework:spring-webflux 5.3.30 间接依赖 maven
net.jcip:jcip-annotations 1.0 间接依赖 maven
org.springframework.boot:spring-boot-starter-mail 2.7.16 直接依赖 maven
com.google.zxing:core 3.3.1 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-data-permission 1.8.3-snapshot 直接依赖 maven
org.springframework.security:spring-security-core 5.7.11 间接依赖 maven
org.springframework.boot:spring-boot-test 2.7.16 间接依赖 maven
org.apache.logging.log4j:log4j-api 2.17.2 间接依赖 maven
io.netty:netty-transport 4.1.97.Final 间接依赖 maven
org.apache.poi:poi-ooxml 4.1.2 间接依赖 maven
commons-logging:commons-logging 1.2 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-captcha 1.8.3-snapshot 直接依赖 maven
org.dom4j:dom4j 2.1.3 间接依赖 maven
com.github.binarywang:qrcode-utils 1.1 间接依赖 maven
org.jeecgframework.jimureport:jimureport-font 1.1.0 间接依赖 maven
org.mapstruct:mapstruct-processor 1.5.5.Final 直接依赖 maven
org.reflections:reflections 0.10.2 间接依赖 maven
org.webjars:swagger-ui 4.17.1 间接依赖 maven
com.github.binarywang:weixin-java-common 4.5.0 间接依赖 maven
org.springframework.security:spring-security-rsa 1.0.11.RELEASE 间接依赖 maven
org.jeecgframework:minidao-spring-boot-starter 1.9.2 间接依赖 maven
org.hamcrest:hamcrest 2.2 间接依赖 maven
org.flowable:flowable-batch-service-api 6.8.0 间接依赖 maven
ch.qos.logback:logback-core 1.2.12 间接依赖 maven
com.xingyuv:spring-boot-starter-justauth 1.0.5 直接依赖 maven
cn.iocoder.cloud:yudao-module-bpm-api 1.8.3-snapshot 直接依赖 maven
com.github.xiaoymin:knife4j-openapi3-spring-boot-starter 4.3.0 直接依赖 maven
org.jacoco:org.jacoco.agent 0.8.10 间接依赖 maven
org.apache.commons:commons-email 1.5 间接依赖 maven
org.springframework.boot:spring-boot-starter-data-redis 2.7.16 间接依赖 maven
io.netty:netty-handler-ssl-ocsp 4.1.97.Final 间接依赖 maven
io.github.resilience4j:resilience4j-spring-boot2 1.7.1 直接依赖 maven
io.netty:netty-codec-smtp 4.1.97.Final 间接依赖 maven
cn.hutool:hutool-all 5.8.22 直接依赖 maven
io.github.openfeign:feign-core 11.10 直接依赖 maven
org.springframework.boot:spring-boot-starter-aop 2.7.16 直接依赖 maven
com.google.guava:guava 32.1.2-jre 直接依赖 maven
com.github.virtuald:curvesapi 1.06 间接依赖 maven
com.aliyun:aliyun-java-sdk-dysmsapi 2.2.1 直接依赖 maven
org.checkerframework:checker-qual 3.33.0 间接依赖 maven
org.apache.commons:commons-math3 3.6.1 间接依赖 maven
io.netty:netty-resolver-dns 4.1.97.Final 间接依赖 maven
org.springframework:spring-beans 5.3.30 间接依赖 maven
org.springframework.cloud:spring-cloud-loadbalancer 3.1.5 直接依赖 maven
org.flowable:flowable-event-registry-json-converter 6.8.0 间接依赖 maven
org.springframework.security:spring-security-crypto 5.7.11 间接依赖 maven
org.springframework.boot:spring-boot-starter-security 2.7.16 直接依赖 maven
commons-net:commons-net 3.9.0 直接依赖 maven
io.projectreactor.addons:reactor-extra 3.4.10 间接依赖 maven
org.flowable:flowable-engine 6.8.0 间接依赖 maven
org.flowable:flowable-process-validation 6.8.0 间接依赖 maven
de.codecentric:spring-boot-admin-client 2.7.10 间接依赖 maven
io.prometheus:simpleclient_tracer_otel 0.15.0 间接依赖 maven
de.codecentric:spring-boot-admin-starter-client 2.7.10 直接依赖 maven
org.tinyjee.jgraphx:jgraphx 1.10.4.1 间接依赖 maven
org.flowable:flowable-event-registry 6.8.0 间接依赖 maven
org.bouncycastle:bcprov-jdk15on 1.70 间接依赖 maven
org.springframework.integration:spring-integration-jmx 5.5.19 间接依赖 maven
org.flowable:flowable-form-model 6.8.0 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-weixin 1.8.3-snapshot 直接依赖 maven
org.springframework.cloud:spring-cloud-bus 3.1.2 间接依赖 maven
org.flowable:flowable-bpmn-model 6.8.0 间接依赖 maven
io.prometheus:simpleclient_common 0.15.0 间接依赖 maven
org.mockito:mockito-core 4.5.1 间接依赖 maven
org.assertj:assertj-core 3.22.0 间接依赖 maven
org.apache.rocketmq:rocketmq-logging 4.9.4 间接依赖 maven
org.apache.poi:poi 4.1.2 间接依赖 maven
io.github.resilience4j:resilience4j-core 1.7.0 间接依赖 maven
org.xerial.snappy:snappy-java 1.1.10.1 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-file 1.8.3-snapshot 直接依赖 maven
org.unbescape:unbescape 1.1.6.RELEASE 间接依赖 maven
org.apache.velocity:velocity-engine-core 2.3 直接依赖 maven
org.springframework:spring-expression 5.3.30 间接依赖 maven
net.bytebuddy:byte-buddy 1.12.23 间接依赖 maven
com.github.xiaoymin:knife4j-core 4.3.0 间接依赖 maven
io.netty:netty-codec-memcache 4.1.97.Final 间接依赖 maven
org.junit.jupiter:junit-jupiter 5.8.2 间接依赖 maven
com.github.yulichang:mybatis-plus-join-extension 1.4.6 间接依赖 maven
io.netty:netty-resolver-dns-classes-macos 4.1.97.Final 间接依赖 maven
org.apache.tika:tika-core 2.7.0 直接依赖 maven
org.flowable:flowable-event-registry-spring-configurator 6.8.0 间接依赖 maven
org.codehaus.groovy:groovy 3.0.19 间接依赖 maven
org.apache.rocketmq:rocketmq-common 4.9.4 间接依赖 maven
ognl:ognl 3.2.21 间接依赖 maven
io.swagger.core.v3:swagger-models 2.2.8 间接依赖 maven
org.apache.rocketmq:rocketmq-acl 4.9.4 间接依赖 maven
io.github.resilience4j:resilience4j-circuitbreaker 1.7.0 间接依赖 maven
cn.iocoder.cloud:yudao-common 1.8.3-snapshot 直接依赖 maven
org.mapstruct:mapstruct-jdk8 1.5.5.Final 直接依赖 maven
org.springframework.boot:spring-boot-actuator-autoconfigure 2.7.16 间接依赖 maven
commons-lang:commons-lang 2.6 间接依赖 maven
org.springframework.security:spring-security-config 5.7.11 间接依赖 maven
com.sun.activation:jakarta.activation 1.2.2 间接依赖 maven
org.springframework.integration:spring-integration-core 5.5.19 间接依赖 maven
org.springdoc:springdoc-openapi-ui 1.6.15 直接依赖 maven
javax.servlet:javax.servlet-api 4.0.1 直接依赖 maven
org.springframework.cloud:spring-cloud-function-core 3.2.8 间接依赖 maven
com.google.code.findbugs:jsr305 3.0.2 间接依赖 maven
io.swagger.core.v3:swagger-core 2.2.8 间接依赖 maven
org.flowable:flowable-spring-boot-starter-actuator 6.8.0 直接依赖 maven
org.flowable:flowable-variable-service 6.8.0 间接依赖 maven
org.flowable:flowable-eventsubscription-service 6.8.0 间接依赖 maven
com.alibaba:fastjson 1.2.83 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-common 1.6.21 间接依赖 maven
org.flowable:flowable-spring 6.8.0 间接依赖 maven
org.junit.platform:junit-platform-engine 1.8.2 间接依赖 maven
io.netty:netty-codec-socks 4.1.97.Final 间接依赖 maven
org.apache.commons:commons-lang3 3.12.0 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-banner 1.8.3-snapshot 直接依赖 maven
org.latencyutils:LatencyUtils 2.0.3 间接依赖 maven
io.projectreactor:reactor-core 3.4.32 间接依赖 maven
com.github.yulichang:mybatis-plus-join-adapter-v352 1.4.6 间接依赖 maven
org.flowable:flowable-image-generator 6.8.0 间接依赖 maven
stax:stax-api 1.0.1 间接依赖 maven
org.bouncycastle:bcpkix-jdk15on 1.69 间接依赖 maven
com.carrotsearch.thirdparty:simple-xml-safe 2.7.1 间接依赖 maven
io.netty:netty-codec-stomp 4.1.97.Final 间接依赖 maven
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml 2.13.5 间接依赖 maven
com.alibaba.cloud:spring-cloud-starter-bus-rocketmq 2021.0.4.0 直接依赖 maven
com.squareup.okio:okio 3.5.0 间接依赖 maven
io.netty:netty-codec-haproxy 4.1.97.Final 间接依赖 maven
org.opentest4j:opentest4j 1.2.0 间接依赖 maven
de.codecentric:spring-boot-admin-server 2.7.10 间接依赖 maven
io.micrometer:micrometer-core 1.9.15 间接依赖 maven
org.flowable:flowable-entitylink-service-api 6.8.0 间接依赖 maven
javax.cache:cache-api 1.1.1 间接依赖 maven
com.github.luben:zstd-jni 1.5.2-2 间接依赖 maven
com.github.binarywang:wx-java-mp-spring-boot-starter 4.5.0 直接依赖 maven
com.oracle.database.jdbc:ojdbc8 21.5.0.0 直接依赖 maven
org.flowable:flowable-job-service-api 6.8.0 间接依赖 maven
org.checkerframework:checker-qual 3.5.0 间接依赖 maven
org.flowable:flowable-spring-common 6.8.0 间接依赖 maven
io.netty:netty-transport-sctp 4.1.97.Final 间接依赖 maven
org.apache.poi:poi-ooxml-schemas 4.1.2 间接依赖 maven
com.baomidou:lock4j-redisson-spring-boot-starter 2.2.3 直接依赖 maven
cn.iocoder.cloud:yudao-module-trade-api 1.8.3-snapshot 直接依赖 maven
com.github.xiaoymin:knife4j-openapi3-ui 4.3.0 间接依赖 maven
io.github.resilience4j:resilience4j-consumer 1.7.0 间接依赖 maven
io.projectreactor.netty:reactor-netty-http 1.0.36 间接依赖 maven
cn.iocoder.cloud:yudao-module-infra-api 1.8.3-snapshot 直接依赖 maven
commons-codec:commons-codec 1.15 间接依赖 maven
com.github.librepdf:openpdf 1.3.27 间接依赖 maven
org.springframework.boot:spring-boot-configuration-processor 2.7.16 直接依赖 maven
org.postgresql:postgresql 42.3.8 直接依赖 maven
com.alibaba.cloud:spring-cloud-starter-alibaba-nacos-discovery 2021.0.4.0 直接依赖 maven
org.springframework.boot:spring-boot-starter-cache 2.7.16 直接依赖 maven
org.springframework:spring-context 5.3.30 间接依赖 maven
cn.iocoder.cloud:yudao-module-pay-api 1.8.3-snapshot 直接依赖 maven
org.springframework:spring-oxm 5.3.30 间接依赖 maven
org.flowable:flowable-event-registry-configurator 6.8.0 间接依赖 maven
javax.activation:javax.activation-api 1.2.0 间接依赖 maven
cn.smallbun.screw:screw-core 1.0.5 直接依赖 maven
org.xmlunit:xmlunit-core 2.9.1 间接依赖 maven
com.alibaba.cloud:spring-cloud-alibaba-commons 2021.0.4.0 间接依赖 maven
io.netty:netty-resolver 4.1.97.Final 间接依赖 maven
com.jayway.jsonpath:json-path 2.7.0 间接依赖 maven
org.springframework:spring-core 5.3.30 间接依赖 maven
com.fasterxml.jackson.core:jackson-annotations 2.13.5 直接依赖 maven
org.javassist:javassist 3.28.0-GA 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-ip 1.8.3-snapshot 直接依赖 maven
org.yaml:snakeyaml 1.30 间接依赖 maven
org.springframework.boot:spring-boot-starter-validation 2.7.16 直接依赖 maven
io.reactivex.rxjava3:rxjava 3.1.5 间接依赖 maven
org.projectlombok:lombok 1.18.30 直接依赖 maven
org.slf4j:jul-to-slf4j 1.7.36 间接依赖 maven
org.apache.skywalking:apm-toolkit-opentracing 8.12.0 直接依赖 maven
org.jboss.marshalling:jboss-marshalling 2.0.11.Final 间接依赖 maven
org.flowable:flowable-identitylink-service 6.8.0 间接依赖 maven
commons-collections:commons-collections 3.2.2 间接依赖 maven
org.jeecgframework:autopoi-web 1.4.6 间接依赖 maven
com.alibaba:easyexcel-core 3.3.2 间接依赖 maven
io.netty:netty-transport-native-epoll 4.1.97.Final 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-rpc 1.8.3-snapshot 直接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-biz-social 1.8.3-snapshot 直接依赖 maven
org.flowable:flowable-idm-api 6.8.0 间接依赖 maven
cn.iocoder.cloud:yudao-spring-boot-starter-mybatis 1.8.3-snapshot 直接依赖 maven
org.flowable:flowable-batch-service 6.8.0 间接依赖 maven
io.github.resilience4j:resilience4j-ratelimiter 1.7.1 间接依赖 maven
org.apache.commons:commons-compress 1.24.0 间接依赖 maven
jakarta.servlet:jakarta.servlet-api 4.0.4 直接依赖 maven
io.minio:minio 8.5.6 直接依赖 maven
com.squareup.okio:okio-jvm 3.5.0 间接依赖 maven
org.lz4:lz4-java 1.8.0 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-jdk7 1.6.21 间接依赖 maven
com.baomidou:mybatis-plus-generator 3.5.3.2 直接依赖 maven
org.flowable:flowable-content-api 6.8.0 间接依赖 maven
org.codehaus.jettison:jettison 1.1 间接依赖 maven
org.flowable:flowable-spring-security 6.8.0 间接依赖 maven
io.vavr:vavr 0.10.2 间接依赖 maven
io.netty:netty-codec-xml 4.1.97.Final 间接依赖 maven
org.flowable:flowable-dmn-api 6.8.0 间接依赖 maven
com.fasterxml:classmate 1.5.1 间接依赖 maven
(0)
上一篇 2023年11月3日
下一篇 2023年11月3日

相关推荐

  • draios/sysdig 软件分析报告

    基础信息 项目名称:draios/sysdig 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721146868578193408/1727838440349196288 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年11月24日
    0
  • alexcrack/angular-ui-notification 软件分析报告

    基础信息 项目名称:alexcrack/angular-ui-notification 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715632185653641216/1715632185854967808 …

    软件分析 2023年10月23日
    0
  • jannson/yaha 软件分析报告

    基础信息 项目名称:jannson/yaha 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721292145796403200/1728401198530650112 此报告由Murphysec提供 漏洞列表 …

    软件分析 2023年11月25日
    0
  • jsonpickle/jsonpickle 软件分析报告

    基础信息 项目名称:jsonpickle/jsonpickle 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1719299728557785088/1719299728624893952 此报告由Murphyse…

    软件分析 2023年10月31日
    0
  • jagrosh/MusicBot 软件分析报告

    基础信息 项目名称:jagrosh/MusicBot 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718941535059099648/1718941536116064256 此报告由Murphysec提供 漏…

    软件分析 2023年10月30日
    0