基础信息
项目名称:yuvraj24/WhatsApp-Clone
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1721684382330691584/1721684382456520704
此报告由Murphysec提供
漏洞列表
| 漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
|---|---|---|---|---|
| libjpeg-turbo 缓冲区错误漏洞 | 越界读取 | MPS-2018-15262 | CVE-2018-19664 | 中危 |
| libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2018-16156 | CVE-2018-20330 | 高危 |
| libjpeg 安全漏洞 | 过度迭代 | MPS-2018-7108 | CVE-2018-11813 | 高危 |
| libjpeg-turbo 安全漏洞 | 除零错误 | MPS-2018-8089 | CVE-2018-1152 | 中危 |
| libjpeg-turbo和MozJPEG 缓冲区错误漏洞 | 越界读取 | MPS-2019-2308 | CVE-2018-14498 | 中危 |
| libjpeg 资源管理错误漏洞 | 不加限制或调节的资源分配 | MPS-2019-8198 | CVE-2019-13960 | 中危 |
| Nanopb 缓冲区错误漏洞 | 越界读取 | MPS-2020-1683 | CVE-2020-5235 | 严重 |
| Nanopb 缓冲区错误漏洞 | 缓冲区溢出 | MPS-2020-16842 | CVE-2020-26243 | 高危 |
| libjpeg-turbo 安全漏洞 | 空指针取消引用 | MPS-2020-35856 | CVE-2020-35538 | 中危 |
| libjpeg-turbo 缓冲区错误漏洞 | 越界读取 | MPS-2020-8147 | CVE-2020-13790 | 高危 |
| libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2021-22766 | CVE-2021-29390 | 严重 |
| DRC libjpeg-turbo 数字错误漏洞 | 除零错误 | MPS-2021-2940 | CVE-2021-20205 | 中危 |
| Nanopb 安全漏洞 | 对无效指针或索引的释放 | MPS-2021-3189 | CVE-2021-21401 | 高危 |
| Libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-2021-7701 | CVE-2020-17541 | 高危 |
| libjpeg 缓冲区错误漏洞 | 越界写入 | MPS-2022-19241 | CVE-2021-46822 | 中危 |
| libjpeg-turbo 缓冲区错误漏洞 | 越界写入 | MPS-ntew-f62l | CVE-2023-2804 | 中危 |
缺陷组件
| 组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
|---|---|---|---|---|
| libjpeg-turbo | 1.5.3 | 3.0.0 | 间接依赖 | 建议修复 |
| nanopb | 0.3.9011 | 2.30908.0 | 间接依赖 | 建议修复 |
许可证风险
| 许可证类型 | 相关组件 | 许可证风险 |
|---|---|---|
| Apache-2.0 | 5 | 低 |
| MIT | 6 | 低 |
| 自定义许可证 | 2 | 低 |
| Zlib | 1 | 低 |
| BSD-3-Clause | 1 | 低 |
SBOM清单
| 组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
|---|---|---|---|
| React-Core/RCTLinkingHeaders | 0.61.5 | 间接依赖 | cocoapods |
| boost-for-react-native | 1.63.0 | 间接依赖 | cocoapods |
| React-RCTSettings | 0.61.5 | 间接依赖 | cocoapods |
| React-Core/DevSupport | 0.61.5 | 间接依赖 | cocoapods |
| react-native-camera | 3.22.1 | 间接依赖 | cocoapods |
| React-Core/RCTWebSocket | 0.61.5 | 间接依赖 | cocoapods |
| libjsinspector.so | 间接依赖 | ||
| com.github.kedzie.supportanimator:sample | 间接依赖 | maven | |
| RNCAsyncStorage | 1.9.0 | 间接依赖 | cocoapods |
| KERNEL32.dll | 间接依赖 | ||
| GoogleUtilities/NSData | 间接依赖 | cocoapods | |
| /System/Library/Frameworks/CoreFoundation.framework/Versions/A/CoreFoundation | 间接依赖 | ||
| RNScreens | 2.4.0 | 间接依赖 | cocoapods |
| com.segment.analytics.android.integrations:firebase | 间接依赖 | maven | |
| libjsc.so | 间接依赖 | ||
| React-Core/RCTSettingsHeaders | 0.61.5 | 间接依赖 | cocoapods |
| React-jsinspector | 0.61.5 | 间接依赖 | cocoapods |
| Firebase/Core | 6.13.0 | 间接依赖 | cocoapods |
| react-native-safe-area-context | 0.7.3 | 间接依赖 | cocoapods |
| React-Core/RCTNetworkHeaders | 0.61.5 | 间接依赖 | cocoapods |
| ReactCommon/jscallinvoker | 0.61.5 | 间接依赖 | cocoapods |
| com.facebook.infer.annotation:infer-annotation | 间接依赖 | maven | |
| RNReanimated | 1.8.0 | 间接依赖 | cocoapods |
| GoogleUtilities/AppDelegateSwizzler | 6.5.1 | 间接依赖 | cocoapods |
| DoubleConversion | 1.1.6 | 间接依赖 | cocoapods |
| GoogleUtilities/Network | 6.5.1 | 间接依赖 | cocoapods |
| FirebaseInstanceID | 4.2.7 | 间接依赖 | cocoapods |
| libc++_shared.so | 间接依赖 | ||
| Firebase/CoreOnly | 6.13.0 | 间接依赖 | cocoapods |
| react-native-camera/RN | 3.22.1 | 间接依赖 | cocoapods |
| libhermes-inspector.so | 间接依赖 | ||
| GoogleUtilities/MethodSwizzler | 6.5.1 | 间接依赖 | cocoapods |
| React-RCTAnimation | 0.61.5 | 间接依赖 | cocoapods |
| RNFBStorage | 6.4.0 | 间接依赖 | cocoapods |
| FirebaseAuthInterop | 1.0.0 | 间接依赖 | cocoapods |
| react-native-contacts | 5.1.0 | 间接依赖 | cocoapods |
| React-jsi/Default | 0.61.5 | 间接依赖 | cocoapods |
| ReactCommon/turbomodule/core | 0.61.5 | 间接依赖 | cocoapods |
| libfolly_json.so | 间接依赖 | ||
| GoogleDataTransportCCTSupport | 1.4.0 | 间接依赖 | cocoapods |
| com.vorlonsoft:androidrate | 间接依赖 | maven | |
| io.homunculus:hcf-codegen | 间接依赖 | maven | |
| RNGestureHandler | 1.6.1 | 间接依赖 | cocoapods |
| com.abubusoft:kripton-arch-integration | 间接依赖 | maven | |
| GoogleDataTransport | 4.0.0 | 间接依赖 | cocoapods |
| glog | 0.3.5 | 间接依赖 | cocoapods |
| GoogleUtilities/Environment | 6.5.1 | 间接依赖 | cocoapods |
| msvcrt.dll | 间接依赖 | ||
| Firebase/Storage | 6.13.0 | 间接依赖 | cocoapods |
| React-RCTNetwork | 0.61.5 | 间接依赖 | cocoapods |
| Folly | 2018.10.22.00 | 间接依赖 | cocoapods |
| libfolly_futures.so | 间接依赖 | ||
| React-RCTVibration | 0.61.5 | 间接依赖 | cocoapods |
| libglog_init.so | 间接依赖 | ||
| /usr/lib/libc++.1.dylib | 间接依赖 | ||
| React-jsiexecutor | 0.61.5 | 间接依赖 | cocoapods |
| GoogleUtilities/Logger | 6.5.1 | 间接依赖 | cocoapods |
| React-Core/RCTTextHeaders | 0.61.5 | 间接依赖 | cocoapods |
| React-RCTLinking | 0.61.5 | 间接依赖 | cocoapods |
| libjnigraphics.so | 间接依赖 | ||
| FirebaseCoreDiagnostics | 1.2.0 | 间接依赖 | cocoapods |
| io.segment.android:analytics | 1.2.0 | 间接依赖 | maven |
| com.facebook.testing.screenshot:layout-hierarchy-litho | 间接依赖 | maven | |
| libm.so | 间接依赖 | ||
| RNFBApp | 6.4.0 | 间接依赖 | cocoapods |
| React-CoreModules | 0.61.5 | 间接依赖 | cocoapods |
| Folly/Default | 2018.10.22.00 | 间接依赖 | cocoapods |
| libfb.so | 间接依赖 | ||
| React-Core/CoreModulesHeaders | 0.61.5 | 间接依赖 | cocoapods |
| FirebaseStorage | 3.4.3 | 间接依赖 | cocoapods |
| React-Core/RCTBlobHeaders | 0.61.5 | 间接依赖 | cocoapods |
| React-Core/RCTImageHeaders | 0.61.5 | 间接依赖 | cocoapods |
| FBReactNativeSpec | 0.61.5 | 间接依赖 | cocoapods |
| React-Core/RCTVibrationHeaders | 0.61.5 | 间接依赖 | cocoapods |
| nanopb | 0.3.9011 | 间接依赖 | cocoapods |
| React-RCTImage | 0.61.5 | 间接依赖 | cocoapods |
| react-native-camera/RCT | 3.22.1 | 间接依赖 | cocoapods |
| GoogleUtilities/UserDefaults | 6.5.1 | 间接依赖 | cocoapods |
| glog | 间接依赖 | ||
| /System/Library/Frameworks/CoreServices.framework/Versions/A/CoreServices | 间接依赖 | ||
| FBLazyVector | 0.61.5 | 间接依赖 | cocoapods |
| React-jsi | 0.61.5 | 间接依赖 | cocoapods |
| React-cxxreact | 0.61.5 | 间接依赖 | cocoapods |
| React-RCTBlob | 0.61.5 | 间接依赖 | cocoapods |
| libhermes.so | 间接依赖 | ||
| libyoga.so | 间接依赖 | ||
| React-Core/RCTAnimationHeaders | 0.61.5 | 间接依赖 | cocoapods |
| libandroid.so | 间接依赖 | ||
| libjpeg-turbo | 1.5.3 | 间接依赖 | |
| React-Core/RCTActionSheetHeaders | 0.61.5 | 间接依赖 | cocoapods |
| React-RCTActionSheet | 0.61.5 | 间接依赖 | cocoapods |
| GoogleUtilities/Reachability | 6.5.1 | 间接依赖 | cocoapods |
| RNCMaskedView | 0.1.9 | 间接依赖 | cocoapods |
| nanopb/decode | 0.3.9011 | 间接依赖 | cocoapods |
| React-RCTText | 0.61.5 | 间接依赖 | cocoapods |
| libstdc++.so | 间接依赖 | ||
| com.facebook.fbjni:fbjni-java-only | 间接依赖 | maven | |
| RCTTypeSafety | 0.61.5 | 间接依赖 | cocoapods |
| com.lotame:cc-android-sdk | 2.3.0.4 | 间接依赖 | maven |
| liblog.so | 间接依赖 | ||
| RNVectorIcons | 6.6.0 | 间接依赖 | cocoapods |
| GTMSessionFetcher/Core | 1.3.1 | 间接依赖 | cocoapods |
| GoogleAppMeasurement | 6.1.6 | 间接依赖 | cocoapods |
| React | 0.61.5 | 间接依赖 | cocoapods |
| /usr/lib/libSystem.B.dylib | 间接依赖 | ||
| FirebaseAnalytics | 6.1.6 | 间接依赖 | cocoapods |
| libc.so | 间接依赖 | ||
| FirebaseCore | 6.4.0 | 间接依赖 | cocoapods |
| React-Core | 0.61.5 | 间接依赖 | cocoapods |
| Yoga | 1.14.0 | 间接依赖 | cocoapods |
| React-Core/Default | 0.61.5 | 间接依赖 | cocoapods |
| libdl.so | 间接依赖 | ||
| FirebaseCoreDiagnosticsInterop | 1.2.0 | 间接依赖 | cocoapods |
| com.google.firebase:firebase-server-sdk | 0.0.3 | 间接依赖 | maven |
| RCTRequired | 0.61.5 | 间接依赖 | cocoapods |
| libreactnativejni.so | 间接依赖 | ||
| nanopb/encode | 0.3.9011 | 间接依赖 | cocoapods |