ipfs-shipyard/gomobile-ipfs 软件分析报告

基础信息

项目名称:ipfs-shipyard/gomobile-ipfs

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721282733564002304/1726651003686051840

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
prometheus client golang 资源管理错误漏洞 不加限制或调节的资源分配 MPS-2021-37056 CVE-2022-21698 高危
Apache Commons IO 存在路径遍历漏洞 路径遍历 MPS-2021-4531 CVE-2021-29425 中危
go-merkledag 安全漏洞 未加检查的返回值 MPS-2022-1922 CVE-2022-23495 高危
Google Golang 资源管理错误漏洞 MPS-2022-58307 CVE-2022-41723 高危
Google Go 权限许可和访问控制问题漏洞 权限管理不当 MPS-2022-9049 CVE-2022-29526 中危
go-unixfs 资源管理错误漏洞 拒绝服务 MPS-2023-1744 CVE-2023-23625 高危
go-bitfield 代码问题漏洞 输入中指定数量的验证不当 MPS-2023-1745 CVE-2023-23626 高危
go-unixfsnode 资源管理错误漏洞 拒绝服务 MPS-2023-1750 CVE-2023-23631 高危
OpenTelemetry-Go Contrib 安全漏洞 不加限制或调节的资源分配 MPS-83gr-xlom CVE-2023-45142 高危
Google Golang 资源管理错误漏洞 拒绝服务 MPS-c8am-hbny CVE-2023-39325 高危
go-libp2p 安全漏洞 不加限制或调节的资源分配 MPS-ej9o-sp7m CVE-2023-39533 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.32.0 0.44.0 间接依赖 建议修复
github.com/ipfs/go-unixfs v0.4.0 0.4.3 间接依赖 建议修复
golang.org/x/net v0.0.0-20220920183852-bf014ff85ad5 0.17.0 间接依赖 建议修复
github.com/ipfs/go-unixfsnode v1.4.0 1.5.2 间接依赖 建议修复
github.com/ipfs/go-bitfield v1.0.0 1.1.0 间接依赖 建议修复
github.com/libp2p/go-libp2p v0.23.3 0.27.8 直接依赖 可选修复
commons-io:commons-io 2.6 2.7 直接依赖 可选修复
golang.org/x/sys v0.0.0-20220915200043-7b5979e65e41 0.1.0 间接依赖 可选修复
github.com/ipfs/go-merkledag v0.6.0 0.8.1 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
MIT 146
Apache-2.0 72
BSD-2-Clause 11
BSD-3-Clause 34
ISC 2
MPL-2.0 4
HPND 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/davidlazar/go-crypto v0.0.0-20200604182044-b73af7476f6c 间接依赖 go
github.com/gabriel-vasile/mimetype v1.4.1 间接依赖 go
github.com/ipfs/go-fs-lock v0.0.7 间接依赖 go
github.com/dgraph-io/badger v1.6.2 间接依赖 go
github.com/ipfs/kubo v0.16.0 直接依赖 go
github.com/mikioh/tcpinfo v0.0.0-20190314235526-30a79bb1804b 间接依赖 go
github.com/polydawn/refmt v0.0.0-20201211092308-30ac6d18308e 间接依赖 go
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 间接依赖 go
github.com/ipfs/go-peertaskqueue v0.7.1 间接依赖 go
github.com/opencontainers/runtime-spec v1.0.2 间接依赖 go
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.1.0 间接依赖 go
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.32.0 间接依赖 go
github.com/pkg/errors v0.9.1 直接依赖 go
github.com/google/gopacket v1.1.19 间接依赖 go
github.com/ipfs/go-ipns v0.3.0 间接依赖 go
github.com/mgutz/ansi v0.0.0-20170206155736-9520e82c474b 间接依赖 go
github.com/felixge/httpsnoop v1.0.3 间接依赖 go
github.com/opentracing/opentracing-go v1.2.0 间接依赖 go
github.com/jbenet/goprocess v0.1.4 间接依赖 go
github.com/libp2p/go-yamux/v4 v4.0.0 间接依赖 go
github.com/AndreasBriese/bbloom v0.0.0-20190825152654-46b345b51c96 间接依赖 go
github.com/whyrusleeping/go-keyspace v0.0.0-20160322163242-5b898ac5add1 间接依赖 go
google.golang.org/appengine v1.6.6 间接依赖 go
github.com/ipfs/go-delegated-routing v0.6.0 间接依赖 go
bazil.org/fuse v0.0.0-20200117225306-7b5117fecadc 间接依赖 go
golang.org/x/exp v0.0.0-20220916125017-b168a2c6b86b 间接依赖 go
github.com/ipld/go-ipld-prime v0.18.0 间接依赖 go
github.com/libp2p/go-buffer-pool v0.1.0 间接依赖 go
go.uber.org/multierr v1.8.0 间接依赖 go
github.com/lucas-clemente/quic-go v0.29.1 间接依赖 go
github.com/multiformats/go-multibase v0.1.1 间接依赖 go
github.com/whyrusleeping/cbor-gen v0.0.0-20210219115102-f37d292932f2 间接依赖 go
github.com/go-logr/stdr v1.2.2 间接依赖 go
github.com/gogo/protobuf v1.3.2 间接依赖 go
github.com/tidwall/match v1.1.1 间接依赖 go
github.com/hannahhoward/go-pubsub v0.0.0-20200423002714-8d62886cc36e 间接依赖 go
github.com/whyrusleeping/base32 v0.0.0-20170828182744-c30ac30633cc 间接依赖 go
github.com/miekg/dns v1.1.50 间接依赖 go
github.com/hashicorp/golang-lru v0.5.4 间接依赖 go
golang.org/x/crypto v0.0.0-20220525230936-793ad666bf5e 间接依赖 go
github.com/mr-tron/base58 v1.2.0 间接依赖 go
github.com/whyrusleeping/tar-utils v0.0.0-20180509141711-8c6c8ba81d5c 间接依赖 go
github.com/ipfs/go-cid v0.3.2 间接依赖 go
github.com/spaolacci/murmur3 v1.1.0 间接依赖 go
github.com/huin/goupnp v1.0.3 间接依赖 go
github.com/go-logr/logr v1.2.3 间接依赖 go
gopkg.in/tomb.v1 v1.0.0-20141024135613-dd632973f1e7 间接依赖 go
github.com/ipld/go-codec-dagpb v1.4.1 间接依赖 go
github.com/ipfs/go-ipfs-redirects-file v0.1.1 间接依赖 go
github.com/ipfs/go-blockservice v0.4.0 间接依赖 go
github.com/mikioh/tcpopt v0.0.0-20190314235656-172688c1accc 间接依赖 go
github.com/ipfs/go-ipld-format v0.4.0 间接依赖 go
github.com/benbjohnson/clock v1.3.0 间接依赖 go
github.com/elastic/gosigar v0.14.2 间接依赖 go
github.com/libp2p/go-libp2p-asn-util v0.2.0 间接依赖 go
go.uber.org/zap v1.23.0 直接依赖 go
github.com/ipfs/go-ipfs-keystore v0.0.2 间接依赖 go
github.com/ipfs/go-ipfs-exchange-interface v0.2.0 间接依赖 go
github.com/marten-seemann/tcp v0.0.0-20210406111302-dfbc87cc63fd 间接依赖 go
github.com/marten-seemann/qtls-go1-18 v0.1.2 间接依赖 go
github.com/ipfs/go-bitfield v1.0.0 间接依赖 go
androidx.appcompat:appcompat 1.3.0 直接依赖 maven
github.com/onsi/ginkgo v1.16.5 间接依赖 go
github.com/ipfs/go-ipfs-api v0.3.0 直接依赖 go
github.com/cespare/xxhash/v2 v2.1.2 间接依赖 go
google.golang.org/grpc v1.47.0 间接依赖 go
google.golang.org/genproto v0.0.0-20211118181313-81c1377c94b1 间接依赖 go
github.com/ipfs/go-verifcid v0.0.2 间接依赖 go
github.com/docker/go-units v0.5.0 间接依赖 go
github.com/ipfs/go-ds-leveldb v0.5.0 间接依赖 go
github.com/libp2p/zeroconf/v2 v2.2.0 直接依赖 go
github.com/libp2p/go-doh-resolver v0.4.0 间接依赖 go
github.com/ipfs/go-ipfs-posinfo v0.0.1 间接依赖 go
golang.org/x/mobile v0.0.0-20201217150744-e6ae53a27f4f 直接依赖 go
github.com/ipfs/go-ipld-legacy v0.1.1 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp v1.7.0 间接依赖 go
github.com/ipfs/go-ipld-git v0.1.1 间接依赖 go
github.com/prometheus/statsd_exporter v0.21.0 间接依赖 go
github.com/libp2p/go-libp2p-pubsub v0.6.1 间接依赖 go
github.com/libp2p/go-netroute v0.2.0 间接依赖 go
github.com/ipfs/go-log v1.0.5 间接依赖 go
github.com/libp2p/go-libp2p v0.23.3 直接依赖 go
github.com/ipfs/go-ds-badger v0.3.0 间接依赖 go
github.com/klauspost/compress v1.15.10 间接依赖 go
github.com/multiformats/go-multiaddr-dns v0.3.1 间接依赖 go
github.com/libp2p/go-libp2p-kad-dht v0.18.0 间接依赖 go
github.com/whyrusleeping/chunker v0.0.0-20181014151217-fe64bd25879f 间接依赖 go
pystache 0.6.0 间接依赖 pip
github.com/ipfs/go-ipfs-routing v0.2.1 间接依赖 go
github.com/ipfs/go-filestore v1.2.0 间接依赖 go
github.com/libp2p/go-msgio v0.2.0 间接依赖 go
github.com/golang/mock v1.6.0 间接依赖 go
github.com/libp2p/go-libp2p-http v0.2.1 间接依赖 go
github.com/whyrusleeping/multiaddr-filter v0.0.0-20160516205228-e903e4adabd7 间接依赖 go
github.com/fsnotify/fsnotify v1.5.4 间接依赖 go
github.com/pbnjay/memory v0.0.0-20210728143218-7b4eea64cf58 间接依赖 go
golang.org/x/oauth2 v0.0.0-20220223155221-ee480838109b 间接依赖 go
github.com/ipfs/go-ipfs-exchange-offline v0.3.0 间接依赖 go
github.com/marten-seemann/webtransport-go v0.1.1 间接依赖 go
github.com/tidwall/gjson v1.14.0 间接依赖 go
github.com/ucarion/urlpath v0.0.0-20200424170820-7ccc79b76bbb 间接依赖 go
github.com/libp2p/go-cidranger v1.1.0 间接依赖 go
github.com/multiformats/go-multiaddr-fmt v0.1.0 直接依赖 go
github.com/gorilla/websocket v1.5.0 间接依赖 go
github.com/multiformats/go-multicodec v0.6.0 间接依赖 go
github.com/ipfs/go-cidutil v0.1.0 间接依赖 go
github.com/marten-seemann/qtls-go1-19 v0.1.0 间接依赖 go
github.com/ipfs/go-path v0.3.0 间接依赖 go
github.com/ipfs/go-ipfs-cmds v0.8.1 间接依赖 go
github.com/ipfs/go-ipfs-util v0.0.2 间接依赖 go
github.com/klauspost/cpuid/v2 v2.1.1 间接依赖 go
github.com/francoispqt/gojay v1.2.13 间接依赖 go
github.com/dustin/go-humanize v1.0.0 间接依赖 go
github.com/crackcomm/go-gitignore v0.0.0-20170627025303-887ab5e44cc3 间接依赖 go
github.com/ipfs/go-graphsync v0.13.1 间接依赖 go
github.com/raulk/go-watchdog v1.3.0 间接依赖 go
github.com/multiformats/go-base36 v0.1.0 间接依赖 go
github.com/multiformats/go-base32 v0.1.0 间接依赖 go
github.com/libp2p/go-reuseport v0.2.0 间接依赖 go
golang.org/x/net v0.0.0-20220920183852-bf014ff85ad5 间接依赖 go
github.com/libp2p/go-libp2p-routing-helpers v0.4.0 间接依赖 go
github.com/libp2p/go-libp2p-record v0.2.0 直接依赖 go
github.com/cespare/xxhash v1.1.0 间接依赖 go
github.com/ceramicnetwork/go-dag-jose v0.1.0 间接依赖 go
github.com/libp2p/go-mplex v0.7.0 间接依赖 go
github.com/koron/go-ssdp v0.0.3 间接依赖 go
github.com/rs/cors v1.7.0 间接依赖 go
golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4 间接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
github.com/facebookgo/atomicfile v0.0.0-20151019160806-2de1f203e7d5 间接依赖 go
github.com/blang/semver/v4 v4.0.0 间接依赖 go
github.com/ipfs/go-ipfs-chunker v0.0.5 间接依赖 go
github.com/ipfs/go-namesys v0.5.0 间接依赖 go
github.com/ipfs/go-ipfs-pinner v0.2.1 间接依赖 go
contrib.go.opencensus.io/exporter/prometheus v0.4.0 间接依赖 go
github.com/marten-seemann/qpack v0.2.1 间接依赖 go
golang.org/x/sys v0.0.0-20220915200043-7b5979e65e41 间接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
github.com/libp2p/go-libp2p-pubsub-router v0.5.0 间接依赖 go
github.com/alexbrainman/goissue34681 v0.0.0-20191006012335-3fc7a47baff5 间接依赖 go
github.com/go-kit/log v0.2.0 间接依赖 go
go.opentelemetry.io/otel/exporters/jaeger v1.7.0 间接依赖 go
github.com/golang/snappy v0.0.4 间接依赖 go
github.com/tidwall/pretty v1.2.0 间接依赖 go
github.com/jackpal/go-nat-pmp v1.0.2 间接依赖 go
github.com/multiformats/go-varint v0.0.6 间接依赖 go
github.com/ipld/go-car v0.4.0 间接依赖 go
github.com/ipfs/go-metrics-interface v0.0.1 间接依赖 go
github.com/libp2p/go-flow-metrics v0.1.0 间接依赖 go
github.com/ipfs/go-bitswap v0.10.2 间接依赖 go
github.com/grpc-ecosystem/grpc-gateway/v2 v2.7.0 间接依赖 go
github.com/wI2L/jsondiff v0.2.0 间接依赖 go
com.journeyapps:zxing-android-embedded 4.2.0 直接依赖 maven
github.com/ipfs/go-log/v2 v2.5.1 间接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.1 间接依赖 go
go.opentelemetry.io/otel/metric v0.30.0 间接依赖 go
github.com/ipfs/go-ipfs-blockstore v1.2.0 间接依赖 go
github.com/ipfs/bbloom v0.0.4 间接依赖 go
github.com/libp2p/go-libp2p-core v0.20.1 间接依赖 go
github.com/syndtr/goleveldb v1.0.0 间接依赖 go
github.com/jbenet/go-temp-err-catcher v0.1.0 间接依赖 go
github.com/ipfs/go-merkledag v0.6.0 间接依赖 go
github.com/mattn/go-runewidth v0.0.4 间接依赖 go
github.com/ipfs/go-datastore v0.6.0 直接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.7.0 间接依赖 go
github.com/ipfs/go-ds-flatfs v0.5.1 间接依赖 go
go.opentelemetry.io/proto/otlp v0.16.0 间接依赖 go
go.opentelemetry.io/otel/exporters/zipkin v1.7.0 间接依赖 go
go.opentelemetry.io/otel/sdk v1.7.0 间接依赖 go
com.google.zxing:core 3.4.1 直接依赖 maven
github.com/ipfs/go-block-format v0.0.3 间接依赖 go
bintray-python 0.8.0 间接依赖 pip
github.com/mattn/go-isatty v0.0.16 间接依赖 go
github.com/libp2p/go-openssl v0.1.0 间接依赖 go
google.golang.org/protobuf v1.28.1 间接依赖 go
github.com/ipfs/go-unixfs v0.4.0 间接依赖 go
github.com/openzipkin/zipkin-go v0.4.0 间接依赖 go
commons-io:commons-io 2.6 直接依赖 maven
go.opentelemetry.io/otel/exporters/stdout/stdouttrace v1.7.0 间接依赖 go
github.com/dgraph-io/ristretto v0.0.2 间接依赖 go
github.com/prometheus/client_model v0.2.0 间接依赖 go
github.com/whyrusleeping/go-sysinfo v0.0.0-20190219211824-4a357d4b90b1 间接依赖 go
github.com/ipfs/go-ipfs-pq v0.0.2 间接依赖 go
github.com/libp2p/go-libp2p-xor v0.1.0 间接依赖 go
github.com/mitchellh/go-homedir v1.1.0 间接依赖 go
go.opentelemetry.io/otel/trace v1.7.0 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/internal/retry v1.7.0 间接依赖 go
go.uber.org/dig v1.14.1 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 间接依赖 go
github.com/ipfs/go-ipfs-provider v0.7.1 间接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
golang.org/x/xerrors v0.0.0-20220609144429-65e65417b02f 间接依赖 go
github.com/minio/sha256-simd v1.0.0 间接依赖 go
go.uber.org/fx v1.17.1 间接依赖 go
github.com/libp2p/go-libp2p-discovery v0.7.0 间接依赖 go
github.com/libp2p/go-nat v0.1.0 间接依赖 go
github.com/ipfs/go-mfs v0.2.1 间接依赖 go
github.com/go-logfmt/logfmt v0.5.1 间接依赖 go
github.com/ipld/go-car/v2 v2.4.0 间接依赖 go
lukechampine.com/blake3 v1.1.7 间接依赖 go
github.com/spacemonkeygo/spacelog v0.0.0-20180420211403-2296661a0572 间接依赖 go
github.com/cenkalti/backoff/v4 v4.1.3 间接依赖 go
github.com/alecthomas/units v0.0.0-20210927113745-59d0afb8317a 间接依赖 go
github.com/ipfs/go-ipfs-ds-help v1.1.0 间接依赖 go
github.com/elgris/jsondiff v0.0.0-20160530203242-765b5c24c302 间接依赖 go
github.com/nxadm/tail v1.4.8 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.7.0 间接依赖 go
github.com/ipld/edelweiss v0.2.0 间接依赖 go
github.com/containerd/cgroups v1.0.4 间接依赖 go
PyYAML 5.4 间接依赖 pip
github.com/go-task/slim-sprig v0.0.0-20210107165309-348f09dbbbc0 间接依赖 go
github.com/flynn/noise v1.0.0 间接依赖 go
github.com/ipfs/tar-utils v0.0.2 间接依赖 go
go4.org v0.0.0-20200411211856-f5505b9728dd 间接依赖 go
github.com/whyrusleeping/timecache v0.0.0-20160911033111-cfcb2f1abfee 间接依赖 go
go.uber.org/atomic v1.10.0 间接依赖 go
gopkg.in/square/go-jose.v2 v2.5.1 间接依赖 go
github.com/ipfs/go-ds-measure v0.2.0 间接依赖 go
github.com/Stebalien/go-bitfield v0.0.1 间接依赖 go
github.com/golang/protobuf v1.5.2 间接依赖 go
github.com/ipfs/go-ipfs-files v0.1.1 直接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/libp2p/go-libp2p-kbucket v0.4.7 间接依赖 go
github.com/cheggaaa/pb v1.0.29 间接依赖 go
github.com/mattn/go-colorable v0.1.4 间接依赖 go
github.com/libp2p/go-libp2p-gostream v0.3.0 间接依赖 go
github.com/prometheus/procfs v0.8.0 间接依赖 go
github.com/ipfs/interface-go-ipfs-core v0.7.0 间接依赖 go
github.com/godbus/dbus/v5 v5.1.0 间接依赖 go
github.com/ipfs/go-fetcher v1.6.1 间接依赖 go
github.com/prometheus/common v0.37.0 间接依赖 go
androidx.constraintlayout:constraintlayout 1.1.3 直接依赖 maven
github.com/ipfs/go-unixfsnode v1.4.0 间接依赖 go
github.com/multiformats/go-multihash v0.2.1 间接依赖 go
github.com/ipfs/go-ipfs-delay v0.0.1 间接依赖 go
golang.org/x/tools v0.1.12 间接依赖 go
golang.org/x/text v0.3.7 间接依赖 go
github.com/ipfs/go-ipld-cbor v0.0.5 间接依赖 go
github.com/mattn/go-pointer v0.0.1 间接依赖 go
github.com/cenkalti/backoff v2.2.1+incompatible 间接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/multiformats/go-multiaddr v0.7.0 直接依赖 go
go.opencensus.io v0.23.0 间接依赖 go
github.com/ipfs/go-pinning-service-http-client v0.1.2 间接依赖 go
github.com/cskr/pubsub v1.0.2 间接依赖 go
go.opentelemetry.io/otel v1.7.0 间接依赖 go
github.com/multiformats/go-multistream v0.3.3 间接依赖 go
github.com/coreos/go-systemd/v22 v22.4.0 间接依赖 go
github.com/prometheus/client_golang v1.13.0 间接依赖 go
(0)
上一篇 2023年11月21日
下一篇 2023年11月21日

相关推荐

  • ebookineur/Markdown-for-Java 软件分析报告

    基础信息 项目名称:ebookineur/Markdown-for-Java 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721154909604151296/1722879668557664256 此报告由M…

    软件分析 2023年11月10日
    0
  • Intermesh/groupoffice 软件分析报告

    基础信息 项目名称:Intermesh/groupoffice 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718849847762403328/1718849848135696384 此报告由Murphyse…

    软件分析 2023年10月30日
    0
  • agarrharr/awesome-cli-apps 软件分析报告

    基础信息 项目名称:agarrharr/awesome-cli-apps 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715560331278598144/1715560331773526016 此报告由Mur…

    软件分析 2023年10月23日
    0
  • drjekyllthemes/themes 软件分析报告

    基础信息 项目名称:drjekyllthemes/themes 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721148398542782464/1729303872721608704 此报告由Murphyse…

    软件分析 2023年11月28日
    0
  • JessYanCoding/MVPArms 软件分析报告

    基础信息 项目名称:JessYanCoding/MVPArms 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721304909570985984/1724181273159098368 此报告由Murphyse…

    软件分析 2023年11月14日
    0