基础信息
项目名称:yuvraj24/WhatsApp-Clone
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1721684382330691584/1721684382456520704
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
libjpeg-turbo 缓冲区错误漏洞 | 越界读取 | MPS-2018-15262 | CVE-2018-19664 | 中危 |
libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2018-16156 | CVE-2018-20330 | 高危 |
libjpeg 安全漏洞 | 过度迭代 | MPS-2018-7108 | CVE-2018-11813 | 高危 |
libjpeg-turbo 安全漏洞 | 除零错误 | MPS-2018-8089 | CVE-2018-1152 | 中危 |
libjpeg-turbo和MozJPEG 缓冲区错误漏洞 | 越界读取 | MPS-2019-2308 | CVE-2018-14498 | 中危 |
libjpeg 资源管理错误漏洞 | 不加限制或调节的资源分配 | MPS-2019-8198 | CVE-2019-13960 | 中危 |
Nanopb 缓冲区错误漏洞 | 越界读取 | MPS-2020-1683 | CVE-2020-5235 | 严重 |
Nanopb 缓冲区错误漏洞 | 缓冲区溢出 | MPS-2020-16842 | CVE-2020-26243 | 高危 |
libjpeg-turbo 安全漏洞 | 空指针取消引用 | MPS-2020-35856 | CVE-2020-35538 | 中危 |
libjpeg-turbo 缓冲区错误漏洞 | 越界读取 | MPS-2020-8147 | CVE-2020-13790 | 高危 |
libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2021-22766 | CVE-2021-29390 | 严重 |
DRC libjpeg-turbo 数字错误漏洞 | 除零错误 | MPS-2021-2940 | CVE-2021-20205 | 中危 |
Nanopb 安全漏洞 | 对无效指针或索引的释放 | MPS-2021-3189 | CVE-2021-21401 | 高危 |
Libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2021-7701 | CVE-2020-17541 | 高危 |
libjpeg 缓冲区错误漏洞 | 越界写入 | MPS-2022-19241 | CVE-2021-46822 | 中危 |
libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-ntew-f62l | CVE-2023-2804 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
libjpeg-turbo | 1.5.3 | 3.0.0 | 间接依赖 | 建议修复 |
nanopb | 0.3.9011 | 2.30908.0 | 间接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 5 | 低 |
MIT | 6 | 低 |
自定义许可证 | 2 | 低 |
Zlib | 1 | 低 |
BSD-3-Clause | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
React-Core/RCTLinkingHeaders | 0.61.5 | 间接依赖 | cocoapods |
boost-for-react-native | 1.63.0 | 间接依赖 | cocoapods |
React-RCTSettings | 0.61.5 | 间接依赖 | cocoapods |
React-Core/DevSupport | 0.61.5 | 间接依赖 | cocoapods |
react-native-camera | 3.22.1 | 间接依赖 | cocoapods |
React-Core/RCTWebSocket | 0.61.5 | 间接依赖 | cocoapods |
libjsinspector.so | 间接依赖 | ||
com.github.kedzie.supportanimator:sample | 间接依赖 | maven | |
RNCAsyncStorage | 1.9.0 | 间接依赖 | cocoapods |
KERNEL32.dll | 间接依赖 | ||
GoogleUtilities/NSData | 间接依赖 | cocoapods | |
/System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation | 间接依赖 | ||
RNScreens | 2.4.0 | 间接依赖 | cocoapods |
com.segment.analytics.android.integrations:firebase | 间接依赖 | maven | |
libjsc.so | 间接依赖 | ||
React-Core/RCTSettingsHeaders | 0.61.5 | 间接依赖 | cocoapods |
React-jsinspector | 0.61.5 | 间接依赖 | cocoapods |
Firebase/Core | 6.13.0 | 间接依赖 | cocoapods |
react-native-safe-area-context | 0.7.3 | 间接依赖 | cocoapods |
React-Core/RCTNetworkHeaders | 0.61.5 | 间接依赖 | cocoapods |
ReactCommon/jscallinvoker | 0.61.5 | 间接依赖 | cocoapods |
com.facebook.infer.annotation:infer-annotation | 间接依赖 | maven | |
RNReanimated | 1.8.0 | 间接依赖 | cocoapods |
GoogleUtilities/AppDelegateSwizzler | 6.5.1 | 间接依赖 | cocoapods |
DoubleConversion | 1.1.6 | 间接依赖 | cocoapods |
GoogleUtilities/Network | 6.5.1 | 间接依赖 | cocoapods |
FirebaseInstanceID | 4.2.7 | 间接依赖 | cocoapods |
libc++_shared.so | 间接依赖 | ||
Firebase/CoreOnly | 6.13.0 | 间接依赖 | cocoapods |
react-native-camera/RN | 3.22.1 | 间接依赖 | cocoapods |
libhermes-inspector.so | 间接依赖 | ||
GoogleUtilities/MethodSwizzler | 6.5.1 | 间接依赖 | cocoapods |
React-RCTAnimation | 0.61.5 | 间接依赖 | cocoapods |
RNFBStorage | 6.4.0 | 间接依赖 | cocoapods |
FirebaseAuthInterop | 1.0.0 | 间接依赖 | cocoapods |
react-native-contacts | 5.1.0 | 间接依赖 | cocoapods |
React-jsi/Default | 0.61.5 | 间接依赖 | cocoapods |
ReactCommon/turbomodule/core | 0.61.5 | 间接依赖 | cocoapods |
libfolly_json.so | 间接依赖 | ||
GoogleDataTransportCCTSupport | 1.4.0 | 间接依赖 | cocoapods |
com.vorlonsoft:androidrate | 间接依赖 | maven | |
io.homunculus:hcf-codegen | 间接依赖 | maven | |
RNGestureHandler | 1.6.1 | 间接依赖 | cocoapods |
com.abubusoft:kripton-arch-integration | 间接依赖 | maven | |
GoogleDataTransport | 4.0.0 | 间接依赖 | cocoapods |
glog | 0.3.5 | 间接依赖 | cocoapods |
GoogleUtilities/Environment | 6.5.1 | 间接依赖 | cocoapods |
msvcrt.dll | 间接依赖 | ||
Firebase/Storage | 6.13.0 | 间接依赖 | cocoapods |
React-RCTNetwork | 0.61.5 | 间接依赖 | cocoapods |
Folly | 2018.10.22.00 | 间接依赖 | cocoapods |
libfolly_futures.so | 间接依赖 | ||
React-RCTVibration | 0.61.5 | 间接依赖 | cocoapods |
libglog_init.so | 间接依赖 | ||
/usr/lib/libc++.1.dylib | 间接依赖 | ||
React-jsiexecutor | 0.61.5 | 间接依赖 | cocoapods |
GoogleUtilities/Logger | 6.5.1 | 间接依赖 | cocoapods |
React-Core/RCTTextHeaders | 0.61.5 | 间接依赖 | cocoapods |
React-RCTLinking | 0.61.5 | 间接依赖 | cocoapods |
libjnigraphics.so | 间接依赖 | ||
FirebaseCoreDiagnostics | 1.2.0 | 间接依赖 | cocoapods |
io.segment.android:analytics | 1.2.0 | 间接依赖 | maven |
com.facebook.testing.screenshot:layout-hierarchy-litho | 间接依赖 | maven | |
libm.so | 间接依赖 | ||
RNFBApp | 6.4.0 | 间接依赖 | cocoapods |
React-CoreModules | 0.61.5 | 间接依赖 | cocoapods |
Folly/Default | 2018.10.22.00 | 间接依赖 | cocoapods |
libfb.so | 间接依赖 | ||
React-Core/CoreModulesHeaders | 0.61.5 | 间接依赖 | cocoapods |
FirebaseStorage | 3.4.3 | 间接依赖 | cocoapods |
React-Core/RCTBlobHeaders | 0.61.5 | 间接依赖 | cocoapods |
React-Core/RCTImageHeaders | 0.61.5 | 间接依赖 | cocoapods |
FBReactNativeSpec | 0.61.5 | 间接依赖 | cocoapods |
React-Core/RCTVibrationHeaders | 0.61.5 | 间接依赖 | cocoapods |
nanopb | 0.3.9011 | 间接依赖 | cocoapods |
React-RCTImage | 0.61.5 | 间接依赖 | cocoapods |
react-native-camera/RCT | 3.22.1 | 间接依赖 | cocoapods |
GoogleUtilities/UserDefaults | 6.5.1 | 间接依赖 | cocoapods |
glog | 间接依赖 | ||
/System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices | 间接依赖 | ||
FBLazyVector | 0.61.5 | 间接依赖 | cocoapods |
React-jsi | 0.61.5 | 间接依赖 | cocoapods |
React-cxxreact | 0.61.5 | 间接依赖 | cocoapods |
React-RCTBlob | 0.61.5 | 间接依赖 | cocoapods |
libhermes.so | 间接依赖 | ||
libyoga.so | 间接依赖 | ||
React-Core/RCTAnimationHeaders | 0.61.5 | 间接依赖 | cocoapods |
libandroid.so | 间接依赖 | ||
libjpeg-turbo | 1.5.3 | 间接依赖 | |
React-Core/RCTActionSheetHeaders | 0.61.5 | 间接依赖 | cocoapods |
React-RCTActionSheet | 0.61.5 | 间接依赖 | cocoapods |
GoogleUtilities/Reachability | 6.5.1 | 间接依赖 | cocoapods |
RNCMaskedView | 0.1.9 | 间接依赖 | cocoapods |
nanopb/decode | 0.3.9011 | 间接依赖 | cocoapods |
React-RCTText | 0.61.5 | 间接依赖 | cocoapods |
libstdc++.so | 间接依赖 | ||
com.facebook.fbjni:fbjni-java-only | 间接依赖 | maven | |
RCTTypeSafety | 0.61.5 | 间接依赖 | cocoapods |
com.lotame:cc-android-sdk | 2.3.0.4 | 间接依赖 | maven |
liblog.so | 间接依赖 | ||
RNVectorIcons | 6.6.0 | 间接依赖 | cocoapods |
GTMSessionFetcher/Core | 1.3.1 | 间接依赖 | cocoapods |
GoogleAppMeasurement | 6.1.6 | 间接依赖 | cocoapods |
React | 0.61.5 | 间接依赖 | cocoapods |
/usr/lib/libSystem.B.dylib | 间接依赖 | ||
FirebaseAnalytics | 6.1.6 | 间接依赖 | cocoapods |
libc.so | 间接依赖 | ||
FirebaseCore | 6.4.0 | 间接依赖 | cocoapods |
React-Core | 0.61.5 | 间接依赖 | cocoapods |
Yoga | 1.14.0 | 间接依赖 | cocoapods |
React-Core/Default | 0.61.5 | 间接依赖 | cocoapods |
libdl.so | 间接依赖 | ||
FirebaseCoreDiagnosticsInterop | 1.2.0 | 间接依赖 | cocoapods |
com.google.firebase:firebase-server-sdk | 0.0.3 | 间接依赖 | maven |
RCTRequired | 0.61.5 | 间接依赖 | cocoapods |
libreactnativejni.so | 间接依赖 | ||
nanopb/encode | 0.3.9011 | 间接依赖 | cocoapods |