基础信息
项目名称:Gitonomy/gitonomy
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1721226273128255488/1726344613593042944
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Sensio Labs Symfony 远程PHP代码注入漏洞 | 代码注入 | MPS-2014-8655 | CVE-2014-4931 | 中危 |
CVE-2014-5244漏洞 | 拒绝服务 | MPS-2014-8738 | CVE-2014-5244 | 中危 |
Sensio Labs Symfony 安全绕过漏洞 | 未授权敏感信息泄露 | MPS-2014-8739 | CVE-2014-5245 | 低危 |
Sensio Labs Symfony 身份验证绕过漏洞 | 认证绕过 | MPS-2014-8834 | CVE-2014-6061 | 低危 |
Sensio 跨站请求伪造漏洞 | CSRF | MPS-2014-8842 | CVE-2014-6072 | 中危 |
Sensio Labs Symfony HttpKernel 代码注入漏洞 | 代码注入 | MPS-2015-2996 | CVE-2015-2308 | 中危 |
Sensio Labs Twig 远程代码执行漏洞 | 权限、特权和访问控制 | MPS-2015-5648 | CVE-2015-7809 | 中危 |
Sensio Labs Symfony 会话固定漏洞 | 会话固定 | MPS-2015-6009 | CVE-2015-8124 | 中危 |
Sensio Labs Symfony 安全漏洞 | 通过时间差异性导致的信息暴露 | MPS-2015-6010 | CVE-2015-8125 | 高危 |
Sensio Labs Symfony 安全绕过漏洞 | 中间人攻击 | MPS-2015-6559 | CVE-2015-2309 | 中危 |
Symphony CMS 跨站脚本漏洞 | XSS | MPS-2016-0153 | CVE-2015-8766 | 中危 |
Sensio Labs Symfony 可预测的随机数生成漏洞 | 密码学问题 | MPS-2016-2654 | CVE-2016-1902 | 高危 |
Sensio Labs Symfony 拒绝服务漏洞 | 资源管理错误 | MPS-2016-2655 | CVE-2016-4423 | 高危 |
多款Zend产品本地提权漏洞 | 权限、特权和访问控制 | MPS-2016-2723 | CVE-2015-5723 | 高危 |
Swift Mailer mail transport 安全漏洞 | 命令注入 | MPS-2016-6443 | CVE-2016-10074 | 严重 |
Sensio Labs Symfony 跨站脚本漏洞 | XSS | MPS-2018-10117 | CVE-2017-18343 | 中危 |
Sensio Labs Symfony HttpKernel 安全漏洞 | HTTP请求走私 | MPS-2018-10833 | CVE-2018-14774 | 高危 |
Symphony 跨站脚本漏洞 | XSS | MPS-2018-7352 | CVE-2018-12043 | 中危 |
Sensio Labs Symfony Security组件安全漏洞 | 会话固定 | MPS-2018-7895 | CVE-2018-11385 | 高危 |
Sensio Labs Symfony HttpFoundation组件安全漏洞 | 不充分的会话过期机制 | MPS-2018-7896 | CVE-2018-11386 | 中危 |
Sensio Labs Symfony Security组件跨站请求伪造漏洞 | CSRF | MPS-2018-7897 | CVE-2018-11406 | 高危 |
Sensio Labs Symfony Ldap组件安全漏洞 | 身份验证不当 | MPS-2018-7898 | CVE-2018-11407 | 严重 |
Sensio Labs Symfony security handlers 安全漏洞 | 跨站重定向 | MPS-2018-7899 | CVE-2018-11408 | 中危 |
Sensio Labs Symfony Web profiler 跨站脚本漏洞 | XSS | MPS-2018-7925 | CVE-2018-12040 | 中危 |
Sensio Labs Twig 信息泄露漏洞 | 未授权敏感信息泄露 | MPS-2019-2892 | CVE-2019-9942 | 低危 |
doctrine/orm 存在SQL注入漏洞 | SQL注入 | MPS-2022-14191 | 中危 | |
monolog/monolog 存在注入漏洞 | 注入 | MPS-2022-14366 | 中危 | |
twig/twig 存在代码注入漏洞 | 代码注入 | MPS-2022-15778 | 高危 | |
Sensio Labs Symfony 授权问题漏洞 | 授权机制不恰当 | MPS-2022-3861 | CVE-2022-24894 | 高危 |
Sensio Labs Symfony 授权问题漏洞 | 会话固定 | MPS-2022-3862 | CVE-2022-24895 | 高危 |
Sensio Labs Twig 路径遍历漏洞 | 路径遍历 | MPS-2022-58285 | CVE-2022-39261 | 高危 |
Symfony 安全漏洞 | XSS | MPS-weax-q6un | CVE-2023-46734 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
swiftmailer/swiftmailer | v5.2.1 | 5.4.5 | 间接依赖 | 强烈建议修复 |
doctrine/common | v2.4.2 | 2.4.3 | 间接依赖 | 建议修复 |
doctrine/cache | v1.3.0 | 1.3.2 | 间接依赖 | 建议修复 |
doctrine/orm | v2.4.4 | 2.8.4 | 间接依赖 | 建议修复 |
doctrine/doctrine-bundle | v1.2.0 | 1.5.2 | 间接依赖 | 建议修复 |
twig/twig | v1.16.0 | 1.44.7 | 间接依赖 | 建议修复 |
symfony/symfony | v2.5.1 | 4.4.51 | 间接依赖 | 建议修复 |
doctrine/annotations | v1.2.0 | 1.2.7 | 间接依赖 | 建议修复 |
monolog/monolog | 1.10.0 | 1.12.0 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 36 | 低 |
LGPL-2.0 | 6 | 中 |
BSD-3-Clause | 1 | 低 |
BSD-2-Clause | 1 | 低 |
BSD-4-Clause | 1 | 低 |
GPL-3.0 | 1 | 中 |
Apache-2.0 | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
symfony/console | 间接依赖 | composer | |
gitonomy/gitlib | v0.1.7 | 间接依赖 | composer |
psr/log | 1.0.0 | 间接依赖 | composer |
doctrine/inflector | v1.0 | 间接依赖 | composer |
jdorn/sql-formatter | v1.2.17 | 间接依赖 | composer |
sensio/distribution-bundle | v2.3.4 | 间接依赖 | composer |
doctrine/data-fixtures | v1.0.0 | 间接依赖 | composer |
symfony/config | 间接依赖 | composer | |
doctrine/lexer | v1.0 | 间接依赖 | composer |
symfony/http-kernel | 间接依赖 | composer | |
twig/twig | v1.16.0 | 间接依赖 | composer |
alexandresalome/mailcatcher | v0.2.0 | 间接依赖 | composer |
juliendidier/buzz-bundle | dev-master | 间接依赖 | composer |
symfony/process | 间接依赖 | composer | |
doctrine/collections | v1.2 | 间接依赖 | composer |
symfony/icu | v1.2.1 | 间接依赖 | composer |
symfony/dependency-injection | 间接依赖 | composer | |
doctrine/orm | v2.4.4 | 间接依赖 | composer |
doctrine/dbal | v2.4.2 | 间接依赖 | composer |
symfony/monolog-bundle | v2.6.0 | 间接依赖 | composer |
kriswallsmith/assetic | v1.1.2 | 间接依赖 | composer |
leafo/lessphp | v0.4.0 | 间接依赖 | composer |
symfony/assetic-bundle | v2.3.0 | 间接依赖 | composer |
doctrine/cache | v1.3.0 | 间接依赖 | composer |
monolog/monolog | 1.10.0 | 间接依赖 | composer |
lib-icu | 间接依赖 | composer | |
symfony/intl | 间接依赖 | composer | |
symfony/doctrine-bridge | 间接依赖 | composer | |
symfony/monolog-bridge | 间接依赖 | composer | |
doctrine/common | v2.4.2 | 间接依赖 | composer |
doctrine/doctrine-bundle | v1.2.0 | 间接依赖 | composer |
twig/extensions | v1.1.0 | 间接依赖 | composer |
doctrine/doctrine-fixtures-bundle | v2.2.0 | 间接依赖 | composer |
gitonomy/git-bundle | v0.2.1 | 间接依赖 | composer |
kriswallsmith/buzz | v0.10 | 间接依赖 | composer |
symfony/framework-bundle | 间接依赖 | composer | |
doctrine/annotations | v1.2.0 | 间接依赖 | composer |
symfony/symfony | v2.5.1 | 间接依赖 | composer |
swiftmailer/swiftmailer | v5.2.1 | 间接依赖 | composer |