firecracker-microvm/firecracker-containerd 软件分析报告

基础信息

项目名称:firecracker-microvm/firecracker-containerd

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721198206280339456/1728095292211290112

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Google Golang 资源管理错误漏洞 拒绝服务 MPS-c8am-hbny CVE-2023-39325 高危
CVE-2023-47108漏洞 不加限制或调节的资源分配 MPS-lrfd-7kb6 CVE-2023-47108 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.28.0 0.46.0 间接依赖 可选修复
golang.org/x/net v0.8.0 0.17.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 85
BSD-3-Clause 26
ISC 2
MIT 36
CC-BY-SA-4.0 2
MPL-2.0 2
BSD-2-Clause 3

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
github.com/moby/sys/symlink v0.2.0 间接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
github.com/prometheus/common v0.30.0 间接依赖 go
github.com/cilium/ebpf v0.7.0 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
github.com/davecgh/go-spew v1.1.0 间接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.4 间接依赖 go
github.com/moby/sys/signal v0.7.0 间接依赖 go
github.com/docker/go-metrics v0.0.1 间接依赖 go
golang.org/x/crypto v0.0.0-20220315160706-3147a52a75dd 间接依赖 go
go.mongodb.org/mongo-driver v1.8.3 间接依赖 go
github.com/urfave/cli v1.22.2 间接依赖 go
github.com/opencontainers/go-digest v1.0.0 间接依赖 go
github.com/go-openapi/validate v0.21.0 间接依赖 go
go.mozilla.org/pkcs7 v0.0.0-20200128120323-432b2356ecb1 间接依赖 go
k8s.io/utils v0.0.0-20210930125809-cb0fa318a74b 间接依赖 go
github.com/cespare/xxhash/v2 v2.1.2 间接依赖 go
github.com/miekg/pkcs11 v1.1.1 间接依赖 go
github.com/stefanberger/go-pkcs11uri v0.0.0-20201008174630-78d3cae3a980 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
sigs.k8s.io/yaml v1.2.0 间接依赖 go
k8s.io/component-base v0.22.5 间接依赖 go
github.com/opencontainers/runc v1.1.7 直接依赖 go
github.com/opentracing/opentracing-go v1.2.0 间接依赖 go
github.com/go-logr/stdr v1.2.2 间接依赖 go
github.com/mdlayher/socket v0.2.0 间接依赖 go
github.com/intel/goresctrl v0.2.0 间接依赖 go
github.com/Microsoft/hcsshim v0.9.8 间接依赖 go
github.com/go-openapi/spec v0.20.4 间接依赖 go
github.com/golang/protobuf v1.5.2 间接依赖 go
github.com/miekg/dns v1.1.25 直接依赖 go
github.com/PuerkitoBio/purell v1.1.1 间接依赖 go
go.opencensus.io v0.23.0 间接依赖 go
github.com/go-openapi/jsonpointer v0.19.5 间接依赖 go
gopkg.in/yaml.v3 v3.0.0 间接依赖 go
github.com/sirupsen/logrus v1.8.1 直接依赖 go
github.com/mdlayher/vsock v1.1.1 间接依赖 go
github.com/Microsoft/go-winio v0.5.2 间接依赖 go
github.com/containerd/imgcrypt v1.1.4 间接依赖 go
github.com/containerd/cgroups v1.0.4 间接依赖 go
github.com/containerd/containerd v1.6.20 直接依赖 go
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
golang.org/x/sync v0.1.0 直接依赖 go
github.com/google/go-cmp v0.5.7 间接依赖 go
github.com/fsnotify/fsnotify v1.4.9 间接依赖 go
github.com/go-logr/logr v1.2.2 间接依赖 go
go.uber.org/goleak v1.1.12 直接依赖 go
github.com/containerd/nri v0.1.0 间接依赖 go
github.com/go-ole/go-ole v1.2.4 间接依赖 go
github.com/google/gofuzz v1.2.0 间接依赖 go
github.com/gogo/googleapis v1.4.1 间接依赖 go
github.com/firecracker-microvm/firecracker-go-sdk v0.22.1-0.20220427214706-47505a9cf951 直接依赖 go
github.com/cpuguy83/go-md2man/v2 v2.0.0 间接依赖 go
github.com/shirou/gopsutil v2.18.12+incompatible 直接依赖 go
github.com/containerd/fifo v1.1.0 直接依赖 go
github.com/go-openapi/swag v0.21.1 间接依赖 go
golang.org/x/text v0.8.0 间接依赖 go
github.com/mailru/easyjson v0.7.7 间接依赖 go
github.com/coreos/go-systemd/v22 v22.3.2 间接依赖 go
go.opentelemetry.io/otel/trace v1.3.0 间接依赖 go
github.com/awslabs/tc-redirect-tap v0.0.0-20211025175357-e30dfca224c2 直接依赖 go
github.com/docker/go-units v0.4.0 间接依赖 go
github.com/containers/ocicrypt v1.1.3 间接依赖 go
k8s.io/api v0.22.5 间接依赖 go
github.com/hashicorp/go-multierror v1.1.1 直接依赖 go
github.com/google/uuid v1.3.0 间接依赖 go
github.com/klauspost/compress v1.15.6 间接依赖 go
k8s.io/apimachinery v0.22.5 间接依赖 go
github.com/stretchr/testify v1.7.1 直接依赖 go
k8s.io/cri-api v0.25.0 间接依赖 go
github.com/containerd/go-runc v1.0.0 直接依赖 go
golang.org/x/sys v0.6.0 直接依赖 go
github.com/containerd/go-cni v1.1.6 间接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/emicklei/go-restful v2.16.0+incompatible 间接依赖 go
github.com/blang/semver v3.5.1+incompatible 间接依赖 go
github.com/vishvananda/netlink v1.1.1-0.20210330154013-f5de75959ad5 直接依赖 go
github.com/spf13/pflag v1.0.5 间接依赖 go
github.com/opencontainers/image-spec v1.1.0-rc2.0.20221005185240-3a7f492d3f1b 直接依赖 go
github.com/pelletier/go-toml v1.9.5 直接依赖 go
github.com/containerd/typeurl v1.0.2 直接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/asaskevich/govalidator v0.0.0-20210307081110-f21760c49a8d 间接依赖 go
github.com/josharian/intern v1.0.0 间接依赖 go
github.com/docker/go-events v0.0.0-20190806004212-e31b211e4f1c 间接依赖 go
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.28.0 间接依赖 go
go.opentelemetry.io/otel v1.3.0 间接依赖 go
github.com/PuerkitoBio/urlesc v0.0.0-20170810143723-de5bf2ad4578 间接依赖 go
github.com/containernetworking/cni v1.1.1 直接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
github.com/vishvananda/netns v0.0.0-20210104183010-2eb08e3e575f 间接依赖 go
github.com/go-stack/stack v1.8.1 间接依赖 go
github.com/go-openapi/strfmt v0.21.2 间接依赖 go
github.com/opencontainers/selinux v1.10.1 间接依赖 go
github.com/json-iterator/go v1.1.12 间接依赖 go
golang.org/x/net v0.8.0 间接依赖 go
github.com/containernetworking/plugins v1.1.1 直接依赖 go
golang.org/x/time v0.0.0-20210723032227-1f47c861a9ac 间接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
github.com/imdario/mergo v0.3.12 间接依赖 go
github.com/prometheus/client_model v0.2.0 间接依赖 go
sigs.k8s.io/structured-merge-diff/v4 v4.1.2 间接依赖 go
github.com/go-openapi/loads v0.21.1 间接依赖 go
go.etcd.io/bbolt v1.3.6 间接依赖 go
github.com/go-openapi/analysis v0.21.2 间接依赖 go
k8s.io/apiserver v0.22.5 间接依赖 go
github.com/moby/sys/mountinfo v0.6.2 间接依赖 go
github.com/docker/docker-credential-helpers v0.6.4 直接依赖 go
github.com/StackExchange/wmi v0.0.0-20181212234831-e0a55b97c705 间接依赖 go
google.golang.org/genproto v0.0.0-20220617124728-180714bec0ad 间接依赖 go
github.com/shurcooL/sanitized_anchor_name v1.0.0 间接依赖 go
github.com/shirou/w32 v0.0.0-20160930032740-bb4de0191aa4 间接依赖 go
github.com/oklog/ulid v1.3.1 间接依赖 go
k8s.io/client-go v0.22.5 间接依赖 go
github.com/prometheus/client_golang v1.11.1 间接依赖 go
github.com/mitchellh/mapstructure v1.4.3 间接依赖 go
github.com/grpc-ecosystem/go-grpc-middleware v1.3.0 间接依赖 go
github.com/containerd/console v1.0.3 间接依赖 go
github.com/modern-go/reflect2 v1.0.2 间接依赖 go
google.golang.org/grpc v1.47.0 直接依赖 go
github.com/hashicorp/errwrap v1.1.0 间接依赖 go
github.com/pkg/errors v0.9.1 间接依赖 go
github.com/firecracker-microvm/firecracker-containerd v0.0.0-20220430002346-5f6efb9fdce8 直接依赖 go
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 间接依赖 go
github.com/russross/blackfriday/v2 v2.0.1 间接依赖 go
github.com/containerd/continuity v0.3.0 直接依赖 go
gopkg.in/square/go-jose.v2 v2.5.1 间接依赖 go
github.com/containerd/ttrpc v1.1.2 直接依赖 go
github.com/emicklei/go-restful/v3 v3.8.0 间接依赖 go
golang.org/x/term v0.6.0 间接依赖 go
github.com/go-openapi/jsonreference v0.19.6 间接依赖 go
github.com/containerd/stargz-snapshotter v0.11.3 直接依赖 go
gopkg.in/inf.v0 v0.9.1 间接依赖 go
github.com/go-openapi/runtime v0.23.3 间接依赖 go
github.com/go-openapi/errors v0.20.2 间接依赖 go
github.com/tchap/go-patricia v2.2.6+incompatible 间接依赖 go
github.com/stretchr/testify v1.8.1 直接依赖 go
github.com/godbus/dbus/v5 v5.0.6 间接依赖 go
golang.org/x/oauth2 v0.0.0-20210819190943-2bc19b11175f 间接依赖 go
github.com/gogo/protobuf v1.3.2 直接依赖 go
github.com/moby/locker v1.0.1 间接依赖 go
github.com/prometheus/procfs v0.7.3 间接依赖 go
google.golang.org/protobuf v1.28.0 间接依赖 go
github.com/moby/spdystream v0.2.0 间接依赖 go
github.com/opencontainers/runtime-spec v1.0.3-0.20210910115017-0d6cc581aeea 直接依赖 go
github.com/gofrs/uuid v3.3.0+incompatible 直接依赖 go
k8s.io/klog/v2 v2.30.0 间接依赖 go
(0)
上一篇 2023年11月25日
下一篇 2023年11月25日

相关推荐

  • babashka/babashka 软件分析报告

    基础信息 项目名称:babashka/babashka 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716204343699046400/1716204346609893376 此报告由Murphysec提供 …

    软件分析 2023年10月23日
    0
  • Ultimaker/CuraEngine 软件分析报告

    基础信息 项目名称:Ultimaker/CuraEngine 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1754505725511512064/1754505988095913984 此报告由Murphysec…

    软件分析 2024年2月5日
    0
  • okbob/pspg 软件分析报告

    基础信息 项目名称:okbob/pspg 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1755408055533334528/1755408055579471872 此报告由Murphysec提供 漏洞列表 暂无…

    软件分析 2024年2月8日
    0
  • aegypius/overlay 软件分析报告

    基础信息 项目名称:aegypius/overlay 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1720513354291785728/1720513354937708544 此报告由Murphysec提供 漏…

    软件分析 2023年11月4日
    0
  • darrencauthon/AutoMoq 软件分析报告

    基础信息 项目名称:darrencauthon/AutoMoq 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721124205457571840/1725713415820759040 此报告由Murphyse…

    软件分析 2023年11月18日
    0