deepflowys/deepflow 软件分析报告

基础信息

项目名称:deepflowys/deepflow

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721129325167640576/1722650947693940736

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
libpcap 输入验证错误漏洞 缓冲区大小计算不正确 MPS-2019-12602 CVE-2019-15161 中危
libpcap 数据伪造问题漏洞 对数据真实性的验证不充分 MPS-2019-12603 CVE-2019-15162 中危
libpcap 代码问题漏洞 空指针取消引用 MPS-2019-12604 CVE-2019-15163 高危
libpcap 代码问题漏洞 SSRF MPS-2019-12605 CVE-2019-15164 中危
libpcap 输入验证错误漏洞 不加限制或调节的资源分配 MPS-2019-12606 CVE-2019-15165 中危
Gin-Gonic Gin 输入验证错误漏洞 输入验证不恰当 MPS-2023-5119 CVE-2023-26125 高危
Gin 安全漏洞 下载代码缺少完整性检查 MPS-2023-9711 CVE-2023-29401 中危
Google Golang 资源管理错误漏洞 拒绝服务 MPS-c8am-hbny CVE-2023-39325 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
libpcap 1.5.3 1.9.1 间接依赖 建议修复
github.com/gin-gonic/gin v1.8.1 1.9.1 间接依赖 建议修复
golang.org/x/net v0.12.0 0.17.0 直接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 106
MIT 81
BSD-3-Clause 49
MPL-2.0 3
BSD-2-Clause 5
ISC 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/ClickHouse/clickhouse-go/v2 v2.1.0 直接依赖 go
github.com/aws/aws-sdk-go-v2/service/elasticloadbalancingv2 v1.18.20 直接依赖 go
github.com/yusufpapurcu/wmi v1.2.2 间接依赖 go
github.com/aliyun/alibaba-cloud-sdk-go v1.61.1633 直接依赖 go
github.com/smartystreets/assertions v1.2.0 间接依赖 go
github.com/google/gopacket v1.1.19 直接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
github.com/xwb1989/sqlparser v0.0.0-20180606152119-120387863bf2 直接依赖 go
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.13.6 间接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20231016165738-49dd2c1f3d0b 间接依赖 go
github.com/influxdata/influxdb v1.9.7 直接依赖 go
github.com/aws/aws-sdk-go-v2/service/sts v1.16.19 间接依赖 go
github.com/edsrzf/mmap-go v1.1.0 间接依赖 go
github.com/dustin/go-humanize v1.0.0 间接依赖 go
github.com/chenzhuoyu/base64x v0.0.0-20230717121745-296ad89f973d 间接依赖 go
github.com/openshift/client-go v0.0.0-20210422153130-25c8450d1535 直接依赖 go
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.45.0 间接依赖 go
gopkg.in/yaml.v2 v2.4.0 直接依赖 go
github.com/json-iterator/go v1.1.12 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/ec2 v1.63.1 直接依赖 go
github.com/dgraph-io/ristretto v0.1.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/credentials v1.12.21 直接依赖 go
golang.org/x/arch v0.5.0 间接依赖 go
github.com/jmoiron/sqlx v1.3.5 直接依赖 go
github.com/aws/aws-sdk-go-v2/internal/ini v1.3.24 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/elasticloadbalancing v1.14.18 直接依赖 go
github.com/bmizerany/assert v0.0.0-20160611221934-b7ed37b82869 间接依赖 go
github.com/pyroscope-io/pyroscope v0.37.1 直接依赖 go
github.com/prometheus/client_model v0.2.0 间接依赖 go
github.com/deckarep/golang-set v1.8.0 直接依赖 go
github.com/goccy/go-json v0.9.7 间接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.2.1 间接依赖 go
k8s.io/klog/v2 v2.70.0 间接依赖 go
k8s.io/kube-openapi v0.0.0-20220328201542-3ee0da9b0b42 间接依赖 go
github.com/fortytw2/leaktest v1.3.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/sso v1.11.23 间接依赖 go
golang.org/x/crypto v0.11.0 间接依赖 go
github.com/grafana/regexp v0.0.0-20220304095617-2e8d9baf4ac2 间接依赖 go
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 间接依赖 go
github.com/deepflowio/deepflow/server/querier/app/prometheus/router/packet_adapter v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/Knetic/govaluate v3.0.1-0.20171022003610-9aa49832a739+incompatible 直接依赖 go
github.com/cornelk/hashmap v1.0.8 直接依赖 go
github.com/go-playground/locales v0.14.0 间接依赖 go
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 间接依赖 go
github.com/go-playground/validator/v10 v10.10.0 间接依赖 go
github.com/rivo/uniseg v0.2.0 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.19.0 直接依赖 go
sigs.k8s.io/json v0.0.0-20211208200746-9f7c6b3444d2 间接依赖 go
github.com/klauspost/compress v1.15.9 直接依赖 go
github.com/emicklei/go-restful v2.14.2+incompatible 间接依赖 go
github.com/pelletier/go-toml/v2 v2.0.1 间接依赖 go
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
github.com/deepflowio/deepflow/server v0.0.0-20231017074137-795433a9f8d6 直接依赖 go
github.com/mattn/go-sqlite3 v1.14.12 间接依赖 go
github.com/tencentcloud/tencentcloud-sdk-go/tencentcloud/common v1.0.726 直接依赖 go
github.com/mitchellh/mapstructure v1.4.3 直接依赖 go
github.com/imdario/mergo v0.3.12 间接依赖 go
go.opentelemetry.io/collector/pdata v0.66.0 直接依赖 go
github.com/dgryski/go-farm v0.0.0-20190423205320-6a90982ecee2 间接依赖 go
github.com/ugorji/go/codec v1.2.7 间接依赖 go
github.com/deepflowio/deepflow/server/controller/cloud/tencent/expand v0.0.0-00010101000000-000000000000 直接依赖 go
go.opentelemetry.io/otel v1.13.0 间接依赖 go
github.com/bitly/go-simplejson v0.5.0 直接依赖 go
github.com/pyroscope-io/jfr-parser v0.5.2 间接依赖 go
gorm.io/driver/mysql v1.3.4 直接依赖 go
github.com/PuerkitoBio/purell v1.1.1 间接依赖 go
golang.org/x/net v0.12.0 直接依赖 go
github.com/spf13/cobra v1.4.0 直接依赖 go
github.com/deepflowio/deepflow/server/controller/cloud/kubernetes_gather/expand v0.0.0-00010101000000-000000000000 直接依赖 go
golang.org/x/sys v0.10.0 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/leodido/go-urn v1.2.1 间接依赖 go
github.com/gin-contrib/sse v0.1.0 间接依赖 go
google.golang.org/grpc v1.59.0 直接依赖 go
github.com/Workiva/go-datastructures v1.0.53 直接依赖 go
github.com/agiledragon/gomonkey/v2 v2.8.0 直接依赖 go
github.com/go-openapi/swag v0.21.1 间接依赖 go
go.opentelemetry.io/contrib/instrumentation/github.com/gin-gonic/gin/otelgin v0.45.0 直接依赖 go
github.com/josharian/intern v1.0.0 间接依赖 go
k8s.io/utils v0.0.0-20220210201930-3a6ce19ff2f9 间接依赖 go
github.com/grpc-ecosystem/grpc-gateway/v2 v2.18.0 间接依赖 go
github.com/chenzhuoyu/iasm v0.9.0 间接依赖 go
github.com/gorilla/mux v1.8.0 直接依赖 go
github.com/alecthomas/units v0.0.0-20211218093645-b94a6e3cc137 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/eks v1.26.0 直接依赖 go
go.opentelemetry.io/otel/trace v1.13.0 间接依赖 go
github.com/deepflowio/deepflow/message v0.0.0-20231024063437-9d62c24174e9 直接依赖 go
github.com/jonboulle/clockwork v0.3.0 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/mattn/go-runewidth v0.0.14 直接依赖 go
github.com/google/gnostic v0.5.7-v3refs 间接依赖 go
github.com/stretchr/testify v1.8.4 直接依赖 go
iproute2 间接依赖
github.com/pebbe/zmq4 v1.2.9 直接依赖 go
golang.org/x/sys v0.13.0 直接依赖 go
google.golang.org/appengine v1.6.8 间接依赖 go
github.com/gopherjs/gopherjs v0.0.0-20190812055157-5d271430af9f 间接依赖 go
github.com/spf13/pflag v1.0.5 间接依赖 go
go.opentelemetry.io/otel/sdk v1.19.0 直接依赖 go
github.com/deepflowio/deepflow/server/querier/app/prometheus/service/packet_wrapper v0.0.0-00010101000000-000000000000 直接依赖 go
golang.org/x/net v0.17.0 直接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.2-0.20181231171920-c182affec369 间接依赖 go
go.opentelemetry.io/otel/trace v1.19.0 直接依赖 go
github.com/go-openapi/jsonpointer v0.19.5 间接依赖 go
github.com/deepflowio/deepflow/message v0.0.0-20231030104748-8f4df11270ae 直接依赖 go
github.com/deepflowio/deepflow/server/controller/monitor/license v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/deepflowio/deepflow/server/controller/http/appender v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.12.17 间接依赖 go
github.com/golang/snappy v0.0.4 直接依赖 go
github.com/shirou/gopsutil v3.21.11+incompatible 直接依赖 go
libpcap 1.5.3 间接依赖
github.com/deepflowio/tempopb v0.0.0-20230215110519-15853baf3a79 直接依赖 go
github.com/felixge/httpsnoop v1.0.3 间接依赖 go
gorm.io/gorm v1.23.5 直接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.9.17 间接依赖 go
github.com/dennwc/varint v1.0.0 间接依赖 go
github.com/deepflowio/deepflow/server/controller/db/mysql/migrator v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/valyala/bytebufferpool v1.0.0 间接依赖 go
github.com/bxcodec/faker/v3 v3.8.0 直接依赖 go
github.com/mattn/go-isatty v0.0.20 间接依赖 go
github.com/mwitkow/go-conntrack v0.0.0-20190716064945-2f068394615f 间接依赖 go
github.com/golang/glog v1.1.2 间接依赖 go
github.com/go-playground/validator/v10 v10.15.5 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.19.0 直接依赖 go
github.com/openshift/api v0.0.0-20210422150128-d8a48168c81c 间接依赖 go
github.com/grafana/pyroscope-go/godeltaprof v0.1.4 间接依赖 go
github.com/deepflowio/deepflow/server/querier/app/tracing-adapter/service/packet_service v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/vishvananda/netlink v1.1.0 直接依赖 go
github.com/emicklei/go-restful v2.16.0+incompatible 间接依赖 go
github.com/OneOfOne/xxhash v1.2.8 直接依赖 go
github.com/inconshreveable/mousetrap v1.0.0 间接依赖 go
github.com/goccy/go-json v0.10.2 直接依赖 go
github.com/grafana/pyroscope-go v1.0.4 直接依赖 go
go.uber.org/atomic v1.10.0 间接依赖 go
github.com/bytedance/sonic v1.10.2 间接依赖 go
github.com/mailru/easyjson v0.7.7 间接依赖 go
github.com/jinzhu/inflection v1.0.0 间接依赖 go
golang.org/x/term v0.10.0 间接依赖 go
google.golang.org/protobuf v1.31.0 间接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
gopkg.in/ini.v1 v1.66.2 间接依赖 go
github.com/lestrrat-go/strftime v1.0.6 间接依赖 go
github.com/mikioh/ipaddr v0.0.0-20190404000644-d465c8ab6721 直接依赖 go
github.com/prometheus/prometheus v0.36.2 直接依赖 go
libc.so.6 间接依赖
github.com/go-logr/stdr v1.2.2 间接依赖 go
gorm.io/driver/sqlite v1.3.4 直接依赖 go
github.com/shopspring/decimal v1.3.1 间接依赖 go
github.com/tklauser/go-sysconf v0.3.10 间接依赖 go
github.com/ugorji/go/codec v1.2.11 间接依赖 go
github.com/mattn/go-isatty v0.0.14 间接依赖 go
github.com/smartystreets/goconvey v1.7.2 直接依赖 go
golang.org/x/time v0.3.0 间接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
golang.org/x/sync v0.4.0 直接依赖 go
python-socketio 5.8.0 间接依赖 pip
github.com/gin-gonic/gin v1.9.1 直接依赖 go
github.com/leodido/go-urn v1.2.4 间接依赖 go
google.golang.org/genproto/googleapis/api v0.0.0-20231016165738-49dd2c1f3d0b 间接依赖 go
go.opentelemetry.io/proto/otlp v1.0.0 直接依赖 go
google.golang.org/genproto/googleapis/rpc v0.0.0-20230711160842-782d3b101e98 间接依赖 go
golang.org/x/term v0.13.0 间接依赖 go
github.com/go-openapi/jsonreference v0.19.6 间接依赖 go
github.com/go-ole/go-ole v1.2.6 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/aws/aws-sdk-go-v2 v1.17.3 直接依赖 go
github.com/deepflowio/deepflow/server/controller/http/service/configuration v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/olekukonko/tablewriter v0.0.5 直接依赖 go
k8s.io/api v0.24.0 直接依赖 go
google.golang.org/grpc v1.58.0 直接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
github.com/ionos-cloud/sdk-go/v6 v6.1.0 间接依赖 go
github.com/go-sql-driver/mysql v1.6.0 间接依赖 go
github.com/dgraph-io/badger/v2 v2.2007.2 间接依赖 go
github.com/prometheus/client_golang v1.12.2 间接依赖 go
github.com/gogo/protobuf v1.3.2 直接依赖 go
go.uber.org/multierr v1.8.0 间接依赖 go
golang.org/x/time v0.0.0-20220224211638-0e9765cccd65 间接依赖 go
github.com/paulmach/orb v0.7.1 间接依赖 go
go.uber.org/goleak v1.1.12 间接依赖 go
github.com/olivere/elastic v6.2.37+incompatible 直接依赖 go
github.com/klauspost/cpuid/v2 v2.2.5 间接依赖 go
github.com/golang/protobuf v1.5.3 直接依赖 go
github.com/twitchyliquid64/golang-asm v0.15.1 间接依赖 go
golang.org/x/oauth2 v0.13.0 间接依赖 go
github.com/cenkalti/backoff/v4 v4.2.1 间接依赖 go
github.com/sirupsen/logrus v1.8.1 间接依赖 go
requests 2.31.0 间接依赖 pip
gopkg.in/alexcesaro/statsd.v2 v2.0.0 直接依赖 go
github.com/go-playground/universal-translator v0.18.0 间接依赖 go
github.com/power-devops/perfstat v0.0.0-20210106213030-5aafc221ea8c 间接依赖 go
github.com/aws/aws-sdk-go-v2/config v1.17.8 直接依赖 go
github.com/jtolds/gls v4.20.0+incompatible 间接依赖 go
golang.org/x/exp v0.0.0-20231006140011-7918f672742d 直接依赖 go
inet.af/netaddr v0.0.0-20211027220019-c74959edd3b6 直接依赖 go
github.com/deckarep/golang-set/v2 v2.1.0 直接依赖 go
github.com/docker/go-units v0.4.0 直接依赖 go
github.com/aws/aws-sdk-go-v2/internal/configsources v1.1.27 间接依赖 go
go4.org/unsafe/assume-no-moving-gc v0.0.0-20230426161633-7e06285ff160 间接依赖 go
github.com/satori/go.uuid v1.2.1-0.20181028125025-b2ce2384e17b 直接依赖 go
github.com/deepflowio/deepflow/server/querier/engine/clickhouse/packet_batch v0.0.0-00010101000000-000000000000 直接依赖 go
github.com/jpillora/backoff v1.0.0 间接依赖 go
github.com/prometheus/procfs v0.7.3 间接依赖 go
github.com/pelletier/go-toml/v2 v2.1.0 间接依赖 go
github.com/op/go-logging v0.0.0-20160315200505-970db520ece7 直接依赖 go
github.com/aws/smithy-go v1.13.5 间接依赖 go
github.com/go-logr/logr v1.2.4 间接依赖 go
github.com/baidubce/bce-sdk-go v0.9.141 直接依赖 go
github.com/go-playground/locales v0.14.1 间接依赖 go
github.com/go-playground/universal-translator v0.18.1 间接依赖 go
k8s.io/apimachinery v0.24.0 直接依赖 go
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.4.21 间接依赖 go
skywalking.apache.org/repo/goapi v0.0.0-20230712035303-201c1fb2d6ec 直接依赖 go
github.com/lestrrat-go/file-rotatelogs v2.4.0+incompatible 直接依赖 go
go.opentelemetry.io/otel/metric v1.19.0 间接依赖 go
github.com/aws/aws-sdk-go v1.44.37 间接依赖 go
github.com/jinzhu/now v1.1.5 间接依赖 go
github.com/tklauser/numcpus v0.4.0 间接依赖 go
github.com/pierrec/lz4/v4 v4.1.15 间接依赖 go
github.com/gin-gonic/gin v1.8.1 间接依赖 go
github.com/prometheus/common v0.35.0 直接依赖 go
github.com/cespare/xxhash/v2 v2.2.0 间接依赖 go
github.com/prometheus/common/sigv4 v0.1.0 间接依赖 go
gopkg.in/inf.v0 v0.9.1 间接依赖 go
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f 间接依赖 go
github.com/go-logr/logr v1.2.3 间接依赖 go
golang.org/x/text v0.13.0 间接依赖 go
github.com/deepflowio/deepflow/server/controller/cloud/platform v0.0.0-00010101000000-000000000000 直接依赖 go
golang.org/x/oauth2 v0.10.0 间接依赖 go
gopkg.in/yaml.v3 v3.0.1 直接依赖 go
github.com/spf13/cobra v1.5.0 直接依赖 go
k8s.io/client-go v0.24.0 直接依赖 go
ld-linux-aarch64.so.1 间接依赖
golang.org/x/crypto v0.14.0 间接依赖 go
github.com/google/gofuzz v1.2.0 间接依赖 go
go.opentelemetry.io/otel v1.19.0 直接依赖 go
github.com/oklog/ulid v1.3.1 间接依赖 go
github.com/vishvananda/netns v0.0.0-20191106174202-0a2b9b5464df 间接依赖 go
github.com/go-logfmt/logfmt v0.5.1 间接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
github.com/gabriel-vasile/mimetype v1.4.3 间接依赖 go
github.com/lufia/plan9stats v0.0.0-20211012122336-39d0f177ccd0 间接依赖 go
go4.org/intern v0.0.0-20211027215823-ae77deb06f29 间接依赖 go
github.com/DataDog/zstd v1.4.1 间接依赖 go
github.com/textnode/fencer v0.0.0-20121219195347-6baed0e5ef9a 直接依赖 go
github.com/go-redis/redis/v9 v9.0.0-rc.2 直接依赖 go
github.com/go-kit/log v0.2.1 间接依赖 go
golang.org/x/text v0.11.0 间接依赖 go
github.com/google/uuid v1.3.1 直接依赖 go
github.com/cespare/xxhash v1.1.0 间接依赖 go
sigs.k8s.io/yaml v1.3.0 直接依赖 go
github.com/shirou/gopsutil/v3 v3.22.5 直接依赖 go
(0)
上一篇 2023年11月10日
下一篇 2023年11月10日

相关推荐

  • hashicorp/damon 软件分析报告

    基础信息 项目名称:hashicorp/damon 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718495463141408768/1718495463254654977 此报告由Murphysec提供 漏洞…

    软件分析 2023年10月29日
    0
  • CodyHouse/codyhouse-framework 软件分析报告

    基础信息 项目名称:CodyHouse/codyhouse-framework 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716790941804445696/1716790942467145728 此报告由…

    软件分析 2023年10月24日
    0
  • hirohisa/PageController 软件分析报告

    基础信息 项目名称:hirohisa/PageController 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721256673778946048/1723761377520078848 此报告由Murphy…

    软件分析 2023年11月13日
    0
  • ddouble/bsie 软件分析报告

    基础信息 项目名称:ddouble/bsie 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1717092166986940416/1717092167070826496 此报告由Murphysec提供 漏洞列表 …

    软件分析 2023年10月25日
    0
  • KevinOConnor/klipper 软件分析报告

    基础信息 项目名称:KevinOConnor/klipper 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721336240837316608/1728604635839029248 此报告由Murphysec…

    软件分析 2023年11月26日
    0