gomods/athens 软件分析报告

基础信息

项目名称:gomods/athens

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721231794761699328/1728211442477256704

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Google Golang 资源管理错误漏洞 拒绝服务 MPS-c8am-hbny CVE-2023-39325 高危
CVE-2023-47108漏洞 不加限制或调节的资源分配 MPS-lrfd-7kb6 CVE-2023-47108 高危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
golang.org/x/net v0.8.0 0.17.0 间接依赖 可选修复
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.25.0 0.46.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
BSD-3-Clause 27
Apache-2.0 61
MIT 48
MPL-2.0 4
BSD-2-Clause 3
Unicode-DFS-2016 1
ISC 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
google.golang.org/protobuf v1.27.1 间接依赖 go
go.etcd.io/etcd/client/v3 v3.5.9 直接依赖 go
go.etcd.io/bbolt v1.3.7 间接依赖 go
github.com/fatih/color v1.13.0 直接依赖 go
github.com/golang/groupcache v0.0.0-20210331224755-41bb18bfe9da 间接依赖 go
github.com/prometheus/client_golang v1.11.1 间接依赖 go
github.com/technosophos/moniker v0.0.0-20180509230615-a5dbd03a2245 直接依赖 go
github.com/modern-go/reflect2 v1.0.1 间接依赖 go
github.com/hashicorp/hcl2 v0.0.0-20190503213020-640445e16309 直接依赖 go
github.com/pkg/errors v0.9.1 间接依赖 go
golang.org/x/sys v0.6.0 间接依赖 go
go.etcd.io/etcd/client/v2 v2.305.9 间接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.0.1 间接依赖 go
github.com/prometheus/procfs v0.6.0 间接依赖 go
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd 间接依赖 go
github.com/mattn/go-isatty v0.0.14 间接依赖 go
github.com/go-redis/redis/v8 v8.11.4 直接依赖 go
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.25.0 间接依赖 go
github.com/klauspost/cpuid v1.2.3 间接依赖 go
golang.org/x/sync v0.0.0-20220722155255-886fb9371eb4 直接依赖 go
github.com/jonboulle/clockwork v0.2.2 间接依赖 go
golang.org/x/time v0.0.0-20210220033141-f8bda1e9f3ba 间接依赖 go
cloud.google.com/go/compute v0.1.0 间接依赖 go
golang.org/x/oauth2 v0.0.0-20211104180415-d3ed0bb246c8 直接依赖 go
github.com/go-stack/stack v1.8.0 间接依赖 go
github.com/philhofer/fwd v1.0.0 间接依赖 go
github.com/joho/godotenv v1.3.0 间接依赖 go
github.com/tinylib/msgp v1.0.2 间接依赖 go
github.com/jmespath/go-jmespath v0.4.0 间接依赖 go
github.com/gobuffalo/envy v1.7.0 直接依赖 go
go.etcd.io/etcd/api/v3 v3.5.9 间接依赖 go
github.com/grpc-ecosystem/go-grpc-middleware v1.3.0 间接依赖 go
go.opentelemetry.io/otel v1.0.1 间接依赖 go
github.com/uber/jaeger-client-go v2.25.0+incompatible 间接依赖 go
cloud.google.com/go v0.100.2 间接依赖 go
go.opentelemetry.io/proto/otlp v0.9.0 间接依赖 go
github.com/mattn/go-ieproxy v0.0.0-20190702010315-6dee0af9227d 间接依赖 go
golang.org/x/crypto v0.0.0-20220411220226-7b82a4e95df4 间接依赖 go
gopkg.in/yaml.v3 v3.0.1 间接依赖 go
google.golang.org/genproto v0.0.0-20220211171837-173942840c17 间接依赖 go
github.com/unrolled/secure v0.0.0-20181221173256-0d6b5bb13069 直接依赖 go
gopkg.in/ini.v1 v1.42.0 间接依赖 go
github.com/youmark/pkcs8 v0.0.0-20181117223130-1be2e3e5546d 间接依赖 go
github.com/dustin/go-humanize v1.0.0 间接依赖 go
github.com/bsm/redislock v0.7.2 直接依赖 go
github.com/gorilla/context v1.1.1 间接依赖 go
github.com/pmezard/go-difflib v1.0.0 间接依赖 go
github.com/sirupsen/logrus v1.7.0 直接依赖 go
cloud.google.com/go/iam v0.1.1 间接依赖 go
gopkg.in/go-playground/assert.v1 v1.2.1 间接依赖 go
github.com/spf13/pflag v1.0.5 间接依赖 go
github.com/cenkalti/backoff/v4 v4.1.1 间接依赖 go
github.com/minio/sha256-simd v0.1.1 间接依赖 go
golang.org/x/net v0.8.0 间接依赖 go
github.com/Azure/azure-storage-blob-go v0.10.0 直接依赖 go
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.0.1 间接依赖 go
github.com/google/uuid v1.3.0 直接依赖 go
github.com/stretchr/testify v1.8.1 直接依赖 go
github.com/ajg/form v0.0.0-20160822230020-523a5da1a92f 间接依赖 go
github.com/kylelemons/godebug v1.1.0 间接依赖 go
github.com/minio/md5-simd v1.1.0 间接依赖 go
github.com/apparentlymart/go-textseg v1.0.0 间接依赖 go
go.etcd.io/etcd/raft/v3 v3.5.9 间接依赖 go
go.mongodb.org/mongo-driver v1.7.1 直接依赖 go
github.com/gorilla/websocket v1.4.2 间接依赖 go
golang.org/x/text v0.8.0 间接依赖 go
github.com/xdg-go/pbkdf2 v1.0.0 间接依赖 go
github.com/cespare/xxhash/v2 v2.1.2 间接依赖 go
contrib.go.opencensus.io/exporter/prometheus v0.1.0 直接依赖 go
github.com/matttproud/golang_protobuf_extensions v1.0.1 间接依赖 go
github.com/aws/aws-sdk-go v1.44.220 直接依赖 go
sigs.k8s.io/yaml v1.2.0 间接依赖 go
go.opentelemetry.io/otel/trace v1.0.1 间接依赖 go
github.com/Azure/azure-pipeline-go v0.2.2 间接依赖 go
github.com/minio/minio-go/v6 v6.0.57 直接依赖 go
github.com/xiang90/probing v0.0.0-20190116061207-43a291ad63a2 间接依赖 go
github.com/json-iterator/go v1.1.11 间接依赖 go
github.com/DataDog/opencensus-go-exporter-datadog v0.0.0-20180917103902-e6c7f767dc57 直接依赖 go
go.opencensus.io v0.23.0 直接依赖 go
github.com/codegangsta/negroni v1.0.0 间接依赖 go
go.opentelemetry.io/otel/sdk v1.0.1 间接依赖 go
github.com/hashicorp/go-multierror v1.0.0 直接依赖 go
golang.org/x/mod v0.8.0 直接依赖 go
github.com/gobuffalo/httptest v1.0.4 直接依赖 go
github.com/mitchellh/go-wordwrap v0.0.0-20150314170334-ad45545899c7 间接依赖 go
cloud.google.com/go/storage v1.20.0 直接依赖 go
github.com/gogo/protobuf v1.3.2 间接依赖 go
github.com/rogpeppe/go-internal v1.3.0 间接依赖 go
github.com/mattn/go-colorable v0.1.9 间接依赖 go
github.com/xdg-go/scram v1.0.2 间接依赖 go
github.com/klauspost/compress v1.9.5 间接依赖 go
go.etcd.io/etcd/server/v3 v3.5.9 直接依赖 go
go.uber.org/zap v1.21.0 间接依赖 go
github.com/kelseyhightower/envconfig v1.3.0 直接依赖 go
github.com/coreos/go-semver v0.3.0 间接依赖 go
go.etcd.io/etcd/pkg/v3 v3.5.9 间接依赖 go
github.com/xdg-go/stringprep v1.0.2 间接依赖 go
gopkg.in/DataDog/dd-trace-go.v1 v1.10.0 间接依赖 go
github.com/golang/protobuf v1.5.2 间接依赖 go
contrib.go.opencensus.io/exporter/jaeger v0.2.1 直接依赖 go
github.com/mitchellh/go-homedir v1.1.0 直接依赖 go
go.uber.org/atomic v1.9.0 间接依赖 go
github.com/coreos/go-systemd/v22 v22.3.2 间接依赖 go
github.com/gorilla/mux v1.6.2 直接依赖 go
github.com/soheilhy/cmux v0.1.5 间接依赖 go
github.com/prometheus/client_model v0.2.0 间接依赖 go
github.com/grpc-ecosystem/grpc-gateway v1.16.0 间接依赖 go
cloud.google.com/go/monitoring v1.3.0 间接依赖 go
go.uber.org/multierr v1.7.0 间接依赖 go
google.golang.org/grpc v1.44.0 间接依赖 go
github.com/lib/pq v1.10.7 直接依赖 go
github.com/tmc/grpc-websocket-proxy v0.0.0-20201229170055-e5319fda7802 间接依赖 go
github.com/agext/levenshtein v1.2.1 间接依赖 go
github.com/grpc-ecosystem/go-grpc-prometheus v1.2.0 间接依赖 go
github.com/go-playground/universal-translator v0.16.0 间接依赖 go
github.com/golang/snappy v0.0.3 间接依赖 go
github.com/zclconf/go-cty v0.0.0-20190426224007-b18a157db9e2 间接依赖 go
github.com/DataDog/datadog-go v0.0.0-20180822151419-281ae9f2d895 间接依赖 go
github.com/hashicorp/errwrap v1.0.0 间接依赖 go
github.com/go-sql-driver/mysql v1.6.0 直接依赖 go
cloud.google.com/go/trace v1.1.0 间接依赖 go
github.com/spf13/afero v1.8.2 直接依赖 go
github.com/googleapis/gax-go/v2 v2.1.1 间接依赖 go
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f 间接依赖 go
github.com/google/go-cmp v0.5.9 直接依赖 go
google.golang.org/api v0.67.0 直接依赖 go
gopkg.in/yaml.v2 v2.4.0 间接依赖 go
github.com/golang-jwt/jwt/v4 v4.4.2 间接依赖 go
github.com/beorn7/perks v1.0.1 间接依赖 go
golang.org/x/xerrors v0.0.0-20200804184101-5ec99f83aff1 间接依赖 go
gopkg.in/go-playground/validator.v9 v9.20.2 直接依赖 go
github.com/go-playground/locales v0.12.1 间接依赖 go
github.com/prometheus/common v0.26.0 间接依赖 go
github.com/davecgh/go-spew v1.1.1 间接依赖 go
go.etcd.io/etcd/client/pkg/v3 v3.5.9 间接依赖 go
github.com/BurntSushi/toml v1.0.0 直接依赖 go
contrib.go.opencensus.io/exporter/stackdriver v0.6.0 直接依赖 go
github.com/google/btree v1.0.1 间接依赖 go
gopkg.in/natefinch/lumberjack.v2 v2.0.0 间接依赖 go
google.golang.org/appengine v1.6.7 间接依赖 go
github.com/markbates/hmax v1.0.0 间接依赖 go
(0)
上一篇 2023年11月25日
下一篇 2023年11月25日

相关推荐

  • willviles/ember-useragent 软件分析报告

    基础信息 项目名称:willviles/ember-useragent 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1727107573960105984/1727107578158604288 此报告由Murp…

    软件分析 2023年11月22日
    0
  • EvgSkv/logica 软件分析报告

    基础信息 项目名称:EvgSkv/logica 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721174563189948416/1729384943756730368 此报告由Murphysec提供 漏洞列表…

    软件分析 2023年11月28日
    0
  • ageitgey/face_recognition 软件分析报告

    基础信息 项目名称:ageitgey/face_recognition 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1715560506836254720/1715560507180187648 此报告由Murp…

    软件分析 2023年10月23日
    0
  • xtiankisutsa/MARA_Framework 软件分析报告

    基础信息 项目名称:xtiankisutsa/MARA_Framework 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1727179745472237568/1727179746080411648 此报告由Mu…

    软件分析 2023年11月22日
    0
  • nickjj/docker-flask-example 软件分析报告

    基础信息 项目名称:nickjj/docker-flask-example 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1746748282837303296/1746748291607592960 此报告由Mu…

    软件分析 2024年1月15日
    0