JanusGraph/janusgraph 软件分析报告

基础信息

项目名称:JanusGraph/janusgraph

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1721292711934853120/1729717150842572800

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Eclipse Jetty 资源管理错误漏洞 拒绝服务 MPS-0e59-bdsi CVE-2023-36478 高危
JetBrains Kotlin 缺省权限不正确 MPS-2021-1082 CVE-2020-29582 中危
Eclipse Jetty URI注入漏洞 注入 MPS-2022-18060 CVE-2022-2047 低危
JetBrains Kotlin 加锁机制不恰当 MPS-2022-3233 CVE-2022-24329 中危
Apache Ivy 输入验证不恰当 MPS-2022-67125 CVE-2022-46751 中危
Apache Spark 权限提升漏洞 权限管理不当 MPS-2023-0818 CVE-2023-22946 高危
Okio 安全漏洞 数值类型间的不正确转换 MPS-a2tx-d4fb CVE-2023-3635 高危
Hot Rod 安全漏洞 证书验证不恰当 MPS-b7oj-adm3 CVE-2023-4586 高危
Bouncy Castle 信任管理问题漏洞 证书验证不恰当 MPS-i6w7-d48e CVE-2023-33201 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
org.apache.spark:spark-core_2.12 3.3.2 3.4.0 间接依赖 建议修复
com.squareup.okio:okio 2.8.0 3.4.0 间接依赖 建议修复
org.eclipse.jetty.http2:http2-hpack 9.4.44.v20210927 9.4.53.v20231009 间接依赖 可选修复
io.netty:netty-handler 4.1.101.Final 间接依赖 可选修复
org.eclipse.jetty:jetty-http 9.4.53.v20231009 11.0.16 间接依赖 可选修复
org.bouncycastle:bcprov-jdk15on 1.70 间接依赖 可选修复
org.apache.ivy:ivy 2.5.1 2.5.2 间接依赖 可选修复
org.jetbrains.kotlin:kotlin-stdlib 1.4.10 1.6.0 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
WTFPL 1
Apache-2.0 279
EPL-2.0 31
MIT 26
CDDL-1.1 4
EPL-1.0 8
BSD-3-Clause 9
ISC 1
BSD-2-Clause 4
自定义许可证 26
JSON 1
GPL-2.0 2
MPL-2.0 1
LGPL-2.1-or-later 1
LGPL-2.1 2
CDDL-1.0 1
MPL-1.1 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
net.oneandone.reflections8:reflections8 0.11.7 直接依赖 maven
io.netty:netty-codec 4.1.101.Final 间接依赖 maven
org.apache.kerby:kerb-crypto 1.0.1 间接依赖 maven
org.glassfish.hk2:hk2-locator 2.6.1 间接依赖 maven
org.apache.tinkerpop:gremlin-util 3.7.0 间接依赖 maven
io.netty:netty-resolver-dns 4.1.101.Final 间接依赖 maven
io.cucumber:tag-expressions 3.0.1 间接依赖 maven
com.carrotsearch:hppc 0.9.1 直接依赖 maven
com.google.android:annotations 4.1.1.4 间接依赖 maven
com.squareup:javapoet 1.13.0 间接依赖 maven
com.sun.jersey:jersey-client 1.19.4 间接依赖 maven
io.netty:netty-tcnative-boringssl-static 2.0.61.Final 间接依赖 maven
io.cucumber:messages 15.0.0 间接依赖 maven
org.apache.kerby:kerby-config 1.0.1 间接依赖 maven
ch.qos.logback:logback-core 1.2.11 间接依赖 maven
org.glassfish.jersey.core:jersey-client 2.36 间接依赖 maven
com.fasterxml.jackson.jaxrs:jackson-jaxrs-base 2.12.7 间接依赖 maven
org.ow2.asm:asm-analysis 9.2 间接依赖 maven
org.mindrot:jbcrypt 0.4 间接依赖 maven
org.apache.hadoop:hadoop-client 3.3.6 直接依赖 maven
org.apache.lucene:lucene-spatial-extras 8.11.2 直接依赖 maven
dnsjava:dnsjava 2.1.7 间接依赖 maven
io.github.artsok:rerunner-jupiter 2.1.6 直接依赖 maven
org.apache.kerby:kerby-asn1 1.0.1 间接依赖 maven
com.google.protobuf:protobuf-java-util 3.25.0 直接依赖 maven
org.apache.ivy:ivy 2.5.1 间接依赖 maven
com.github.ben-manes.caffeine:caffeine 2.9.3 直接依赖 maven
io.dropwizard.metrics:metrics-jmx 4.2.22 直接依赖 maven
com.google.guava:listenablefuture 9999.0-empty-to-avoid-conflict-with-guava 间接依赖 maven
org.roaringbitmap:RoaringBitmap 0.9.25 间接依赖 maven
com.google.guava:guava 32.1.3-jre 直接依赖 maven
com.twitter:chill_2.12 0.10.0 间接依赖 maven
org.apache.hadoop:hadoop-annotations 3.3.6 间接依赖 maven
com.fasterxml.jackson.core:jackson-databind 2.15.3 直接依赖 maven
org.eclipse.jetty:jetty-util-ajax 9.4.53.v20231009 间接依赖 maven
org.apache.commons:commons-compress 1.24.0 间接依赖 maven
javax.servlet.jsp:jsp-api 2.1 间接依赖 maven
org.apache.spark:spark-network-common_2.12 3.3.2 间接依赖 maven
io.cucumber:datatable 3.5.0 间接依赖 maven
org.apache.lucene:lucene-analyzers-common 8.11.2 直接依赖 maven
org.eclipse.jetty.http2:http2-client 9.4.44.v20210927 间接依赖 maven
org.apache.tinkerpop:gremlin-server 3.7.0 直接依赖 maven
org.apache.curator:curator-client 5.5.0 直接依赖 maven
org.apache.tinkerpop:hadoop-gremlin 3.7.0 直接依赖 maven
com.github.jnr:jnr-posix 3.1.15 间接依赖 maven
javax.ws.rs:jsr311-api 1.1.1 间接依赖 maven
org.eclipse.jetty:jetty-io 9.4.53.v20231009 间接依赖 maven
org.yaml:snakeyaml 2.2 间接依赖 maven
org.fusesource.jansi:jansi 1.17.1 间接依赖 maven
org.ow2.asm:asm-util 9.2 间接依赖 maven
io.dropwizard.metrics:metrics-core 4.2.22 直接依赖 maven
org.eclipse.jetty:jetty-client 9.4.53.v20231009 间接依赖 maven
org.apache.logging.log4j:log4j-slf4j-impl 2.20.0 直接依赖 maven
org.apache.commons:commons-collections4 4.4 间接依赖 maven
com.google.re2j:re2j 1.1 间接依赖 maven
org.xerial.snappy:snappy-java 1.1.10.5 间接依赖 maven
org.antlr:antlr4-runtime 4.9.1 间接依赖 maven
com.fasterxml.woodstox:woodstox-core 6.5.1 间接依赖 maven
org.apache.lucene:lucene-sandbox 8.11.2 间接依赖 maven
com.fasterxml.jackson.datatype:jackson-datatype-json-org 2.15.3 直接依赖 maven
org.apache.hbase:hbase-shaded-client 2.5.6-hadoop3 直接依赖 maven
org.apache.spark:spark-unsafe_2.12 3.3.2 间接依赖 maven
org.apache.spark:spark-network-shuffle_2.12 3.3.2 间接依赖 maven
org.apache.commons:commons-text 1.10.0 直接依赖 maven
org.ow2.asm:asm 9.6 间接依赖 maven
org.eclipse.jetty:jetty-alpn-java-client 9.4.44.v20210927 间接依赖 maven
org.janusgraph:janusgraph-backend-testutils 1.1.0-SNAPSHOT 直接依赖 maven
io.netty:netty-codec-http 4.1.101.Final 间接依赖 maven
javax.xml.bind:jaxb-api 2.3.1 间接依赖 maven
org.glassfish.hk2:osgi-resource-locator 1.0.3 间接依赖 maven
org.apache.kerby:kerb-simplekdc 1.0.1 间接依赖 maven
org.bouncycastle:bcprov-jdk15on 1.70 间接依赖 maven
com.github.javaparser:javaparser-core 3.25.0 间接依赖 maven
jline:jline 2.14.6 间接依赖 maven
org.json4s:json4s-jackson_2.12 3.7.0-M11 间接依赖 maven
org.apache.groovy:groovy 4.0.9 间接依赖 maven
com.esotericsoftware:kryo-shaded 4.0.2 间接依赖 maven
org.junit.jupiter:junit-jupiter-engine 5.10.0 直接依赖 maven
jakarta.validation:jakarta.validation-api 2.0.2 间接依赖 maven
org.json4s:json4s-core_2.12 3.7.0-M11 间接依赖 maven
io.dropwizard.metrics:metrics-jvm 4.2.22 间接依赖 maven
io.grpc:grpc-stub 1.59.0 直接依赖 maven
org.apache.lucene:lucene-queryparser 8.11.2 直接依赖 maven
org.codehaus.mojo:animal-sniffer-annotations 1.23 间接依赖 maven
org.apache.hadoop:hadoop-mapreduce-client-jobclient 3.3.6 间接依赖 maven
io.netty:netty-codec-redis 4.1.101.Final 间接依赖 maven
org.janusgraph:janusgraph-hbase 1.1.0-SNAPSHOT 直接依赖 maven
com.google.crypto.tink:tink 1.6.1 间接依赖 maven
org.fusesource.leveldbjni:leveldbjni-all 1.8 间接依赖 maven
org.janusgraph:janusgraph-inmemory 1.1.0-SNAPSHOT 直接依赖 maven
com.squareup.okio:okio 2.8.0 间接依赖 maven
org.slf4j:slf4j-api 1.7.36 直接依赖 maven
com.github.luben:zstd-jni 1.5.2-1 间接依赖 maven
io.grpc:grpc-netty-shaded 1.59.0 直接依赖 maven
io.netty:netty-transport-native-epoll 4.1.101.Final 直接依赖 maven
org.janusgraph:janusgraph-driver 1.1.0-SNAPSHOT 直接依赖 maven
org.apache.kerby:kerb-identity 1.0.1 间接依赖 maven
commons-collections:commons-collections 3.2.2 直接依赖 maven
mkdocs-macros-plugin 1.0.4 间接依赖 pip
org.glassfish.hk2.external:aopalliance-repackaged 2.6.1 间接依赖 maven
io.opentelemetry:opentelemetry-api 1.15.0 间接依赖 maven
org.eclipse.jetty:jetty-servlet 9.4.53.v20231009 间接依赖 maven
com.google.protobuf:protobuf-java 3.25.0 直接依赖 maven
org.hamcrest:hamcrest-core 1.3 间接依赖 maven
io.netty:netty-resolver-dns-native-macos 4.1.101.Final 间接依赖 maven
org.apache.avro:avro-ipc 1.11.0 间接依赖 maven
org.apache.groovy:groovy-groovysh 4.0.9 间接依赖 maven
net.razorvine:pickle 1.2 间接依赖 maven
org.apache.tinkerpop:gremlin-groovy 3.7.0 直接依赖 maven
io.vavr:vavr 0.10.4 直接依赖 maven
commons-configuration:commons-configuration 1.10 直接依赖 maven
org.codehaus.woodstox:stax2-api 4.2.2 间接依赖 maven
com.clearspring.analytics:stream 2.9.8 间接依赖 maven
org.json4s:json4s-scalap_2.12 3.7.0-M11 间接依赖 maven
org.apache.commons:commons-math 2.2 直接依赖 maven
org.apache.hadoop:hadoop-yarn-client 3.3.6 间接依赖 maven
org.assertj:assertj-core 3.19.0 间接依赖 maven
org.janusgraph:janusgraph-mixed-index-utils 1.1.0-SNAPSHOT 直接依赖 maven
net.bytebuddy:byte-buddy 1.12.19 间接依赖 maven
com.fasterxml.jackson.core:jackson-annotations 2.15.3 直接依赖 maven
com.datastax.oss:java-driver-shaded-guava 25.1-jre-graal-sub-1 间接依赖 maven
io.netty:netty-transport-udt 4.1.101.Final 间接依赖 maven
io.netty:netty-codec-memcache 4.1.101.Final 间接依赖 maven
net.sf.py4j:py4j 0.10.9.5 间接依赖 maven
Pygments 2.16.1 间接依赖 pip
org.jctools:jctools-core 4.0.1 直接依赖 maven
org.junit.platform:junit-platform-engine 1.10.0 间接依赖 maven
io.cucumber:cucumber-gherkin-messages 6.11.0 间接依赖 maven
com.fasterxml.jackson.module:jackson-module-scala_2.12 2.15.3 直接依赖 maven
org.hamcrest:hamcrest 2.2 间接依赖 maven
jakarta.activation:jakarta.activation-api 1.2.1 间接依赖 maven
commons-beanutils:commons-beanutils 1.9.4 间接依赖 maven
io.grpc:grpc-protobuf-lite 1.59.0 间接依赖 maven
commons-codec:commons-codec 1.15 直接依赖 maven
io.grpc:grpc-protobuf 1.59.0 直接依赖 maven
com.datastax.oss:java-driver-query-builder 4.17.0 直接依赖 maven
commons-net:commons-net 3.9.0 间接依赖 maven
org.apache.hadoop:hadoop-distcp 3.3.6 间接依赖 maven
org.glassfish.jersey.containers:jersey-container-servlet-core 2.36 间接依赖 maven
org.tukaani:xz 1.9 间接依赖 maven
io.netty:netty-common 4.1.101.Final 间接依赖 maven
org.json:json 20231013 间接依赖 maven
pymdown-extensions 10.4 间接依赖 pip
org.noggit:noggit 0.8 直接依赖 maven
org.lz4:lz4-java 1.8.0 间接依赖 maven
io.dropwizard.metrics:metrics-graphite 4.2.22 直接依赖 maven
org.apache.solr:solr-solrj 8.11.2 直接依赖 maven
org.apache.tinkerpop:tinkergraph-gremlin 3.7.0 直接依赖 maven
javax.servlet:javax.servlet-api 4.0.1 间接依赖 maven
com.fasterxml.jackson.module:jackson-module-jaxb-annotations 2.12.7 间接依赖 maven
jinja2 3.1.2 间接依赖 pip
org.locationtech.spatial4j:spatial4j 0.8 直接依赖 maven
org.apache.httpcomponents:httpclient 4.5.14 间接依赖 maven
org.glassfish.jersey.core:jersey-common 2.36 间接依赖 maven
com.esotericsoftware:minlog 1.3.0 间接依赖 maven
org.apache.kerby:kerb-core 1.0.1 间接依赖 maven
commons-io:commons-io 2.11.0 直接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-common 1.4.10 间接依赖 maven
org.apache.tinkerpop:gremlin-shaded 3.7.0 间接依赖 maven
io.grpc:grpc-context 1.59.0 间接依赖 maven
org.apache.hadoop:hadoop-yarn-api 3.3.6 间接依赖 maven
org.glassfish.hk2:hk2-utils 2.6.1 间接依赖 maven
org.janusgraph:janusgraph-all 1.1.0-SNAPSHOT 直接依赖 maven
org.openjdk.jmh:jmh-core 1.37 直接依赖 maven
io.netty:netty-handler-ssl-ocsp 4.1.101.Final 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib 1.4.10 间接依赖 maven
org.janusgraph:janusgraph-hadoop 1.1.0-SNAPSHOT 直接依赖 maven
com.datastax.oss:java-driver-test-infra 4.17.0 直接依赖 maven
commons-cli:commons-cli 1.5.0 间接依赖 maven
org.apache.kerby:kerb-util 1.0.1 间接依赖 maven
org.apache.httpcomponents:httpmime 4.5.13 间接依赖 maven
io.netty:netty-codec-smtp 4.1.101.Final 间接依赖 maven
org.janusgraph:janusgraph-cql 1.1.0-SNAPSHOT 直接依赖 maven
ch.qos.logback:logback-classic 1.2.11 直接依赖 maven
io.cucumber:cucumber-expressions 10.3.0 间接依赖 maven
io.netty:netty-resolver 4.1.101.Final 间接依赖 maven
org.rocksdb:rocksdbjni 6.20.3 间接依赖 maven
info.picocli:picocli 4.7.0 间接依赖 maven
io.cucumber:cucumber-java 6.11.0 间接依赖 maven
org.junit.jupiter:junit-jupiter-params 5.10.0 直接依赖 maven
org.junit.jupiter:junit-jupiter-api 5.10.0 直接依赖 maven
io.netty:netty-transport-classes-kqueue 4.1.101.Final 间接依赖 maven
io.netty:netty-codec-http2 4.1.101.Final 间接依赖 maven
org.elasticsearch.client:elasticsearch-rest-client 8.10.4 直接依赖 maven
io.netty:netty-handler 4.1.101.Final 间接依赖 maven
org.reactivestreams:reactive-streams 1.0.3 间接依赖 maven
org.janusgraph:janusgraph-bigtable 1.1.0-SNAPSHOT 直接依赖 maven
org.glassfish.jersey.inject:jersey-hk2 2.36 间接依赖 maven
net.bytebuddy:byte-buddy-agent 1.12.19 间接依赖 maven
org.locationtech.jts:jts-core 1.17.0 直接依赖 maven
org.glassfish.hk2:hk2-api 2.6.1 间接依赖 maven
io.cucumber:create-meta 4.0.0 间接依赖 maven
org.apache.tinkerpop:gremlin-console 3.7.0 直接依赖 maven
org.glassfish.jersey.containers:jersey-container-servlet 2.36 间接依赖 maven
jakarta.ws.rs:jakarta.ws.rs-api 2.1.6 间接依赖 maven
org.apiguardian:apiguardian-api 1.1.2 间接依赖 maven
io.grpc:grpc-api 1.59.0 间接依赖 maven
com.scylladb:java-driver-core 4.17.0.0 直接依赖 maven
org.apache.groovy:groovy-jsr223 4.0.9 间接依赖 maven
com.jcabi:jcabi-manifests 2.1.0 直接依赖 maven
com.github.jbellis:jamm 0.3.3 直接依赖 maven
org.apache.yetus:audience-annotations 0.13.0 间接依赖 maven
org.apache.kerby:kerby-pkix 1.0.1 间接依赖 maven
org.apache.kerby:kerb-common 1.0.1 间接依赖 maven
org.janusgraph:janusgraph-es 1.1.0-SNAPSHOT 直接依赖 maven
jakarta.xml.bind:jakarta.xml.bind-api 2.3.2 间接依赖 maven
org.apache.tinkerpop:spark-gremlin 3.7.0 直接依赖 maven
org.apache.hadoop:hadoop-common 3.3.6 间接依赖 maven
com.fasterxml.jackson.core:jackson-core 2.15.3 直接依赖 maven
org.apache.tinkerpop:gremlin-test 3.7.0 直接依赖 maven
org.eclipse.jetty.websocket:websocket-api 9.4.51.v20230217 间接依赖 maven
net.sf.jopt-simple:jopt-simple 5.0.4 间接依赖 maven
org.apache.lucene:lucene-core 8.11.2 直接依赖 maven
com.scylladb:java-driver-query-builder 4.17.0.0 直接依赖 maven
io.netty:netty-codec-haproxy 4.1.101.Final 间接依赖 maven
org.glassfish.hk2.external:jakarta.inject 2.6.1 间接依赖 maven
org.bouncycastle:bcutil-jdk15on 1.70 间接依赖 maven
io.grpc:grpc-util 1.59.0 间接依赖 maven
org.apache.hadoop:hadoop-mapreduce-client-core 3.3.6 间接依赖 maven
org.apache.hbase.thirdparty:hbase-noop-htrace 4.1.5 直接依赖 maven
mkdocs-redirects 1.2.1 间接依赖 pip
markdown 3.5.1 间接依赖 pip
org.janusgraph:cassandra-hadoop-util 1.1.0-SNAPSHOT 直接依赖 maven
com.jcabi:jcabi-log 0.22.0 间接依赖 maven
mkdocs-include-markdown-plugin 6.0.2 间接依赖 pip
org.apache.lucene:lucene-queries 8.11.2 间接依赖 maven
org.apache.groovy:groovy-xml 4.0.9 间接依赖 maven
io.netty:netty-transport-classes-epoll 4.1.101.Final 间接依赖 maven
org.eclipse.jetty:jetty-util 9.4.53.v20231009 间接依赖 maven
javax.servlet:servlet-api 2.5 直接依赖 maven
org.scala-lang.modules:scala-xml_2.12 1.2.0 间接依赖 maven
org.apache.groovy:groovy-console 4.0.9 间接依赖 maven
org.apache.spark:spark-kvstore_2.12 3.3.2 间接依赖 maven
io.netty:netty-transport-native-kqueue 4.1.101.Final 间接依赖 maven
io.dropwizard.metrics:metrics-json 4.2.7 间接依赖 maven
org.eclipse.jetty:jetty-xml 9.4.51.v20230217 间接依赖 maven
io.cucumber:cucumber-core 6.11.0 间接依赖 maven
org.apache.spark:spark-launcher_2.12 3.3.2 间接依赖 maven
org.apache.commons:commons-lang3 3.12.0 间接依赖 maven
org.apache.kerby:kerb-server 1.0.1 间接依赖 maven
com.fasterxml.jackson.jaxrs:jackson-jaxrs-json-provider 2.12.7 间接依赖 maven
io.netty:netty-codec-mqtt 4.1.101.Final 间接依赖 maven
org.apache.hadoop:hadoop-client-api 3.3.2 间接依赖 maven
com.github.jnr:jffi 1.3.9 间接依赖 maven
org.eclipse.jetty:jetty-http 9.4.53.v20231009 间接依赖 maven
org.eclipse.jetty.http2:http2-hpack 9.4.44.v20210927 间接依赖 maven
org.apache.spark:spark-tags_2.12 3.3.2 间接依赖 maven
io.cucumber:cucumber-plugin 6.11.0 间接依赖 maven
org.eclipse.jetty:jetty-webapp 9.4.51.v20230217 间接依赖 maven
org.janusgraph:example-common 1.1.0-SNAPSHOT 直接依赖 maven
org.apache.httpcomponents:httpcore 4.4.16 间接依赖 maven
com.google.code.gson:gson 2.10.1 间接依赖 maven
io.netty:netty-resolver-dns-classes-macos 4.1.101.Final 间接依赖 maven
org.janusgraph:janusgraph-solr 1.1.0-SNAPSHOT 直接依赖 maven
com.sun.jersey:jersey-servlet 1.19.4 间接依赖 maven
org.apache.spark:spark-core_2.12 3.3.2 间接依赖 maven
org.janusgraph:janusgraph-server 1.1.0-SNAPSHOT 直接依赖 maven
com.twitter:chill-java 0.10.0 间接依赖 maven
io.cucumber:cucumber-junit 6.11.0 间接依赖 maven
org.janusgraph:janusgraph-core 1.1.0-SNAPSHOT 直接依赖 maven
io.netty:netty-transport-sctp 4.1.101.Final 间接依赖 maven
jakarta.annotation:jakarta.annotation-api 1.3.5 间接依赖 maven
org.ow2.asm:asm-tree 9.2 间接依赖 maven
org.apache.logging.log4j:log4j-api 2.20.0 间接依赖 maven
com.github.jnr:jnr-ffi 2.2.11 间接依赖 maven
org.eclipse.jetty:jetty-alpn-client 9.4.44.v20210927 间接依赖 maven
org.apache.groovy:groovy-json 4.0.9 间接依赖 maven
io.netty:netty-handler-proxy 4.1.101.Final 间接依赖 maven
com.github.stephenc.jcip:jcip-annotations 1.0-1 间接依赖 maven
org.eclipse.jetty.websocket:websocket-common 9.4.51.v20230217 间接依赖 maven
org.janusgraph:janusgraph-berkeleyje 1.1.0-SNAPSHOT 直接依赖 maven
org.bouncycastle:bcpkix-jdk15on 1.70 间接依赖 maven
com.google.cloud.bigtable:bigtable-hbase-2.x-shaded 1.24.0 直接依赖 maven
org.apache.hadoop.thirdparty:hadoop-shaded-guava 1.1.1 间接依赖 maven
org.hamcrest:hamcrest 2.1 间接依赖 maven
com.typesafe:config 1.4.1 间接依赖 maven
org.scala-lang:scala-library 2.12.15 间接依赖 maven
com.github.jnr:jnr-a64asm 1.0.0 间接依赖 maven
org.mockito:mockito-core 4.11.0 直接依赖 maven
org.junit.platform:junit-platform-launcher 1.10.0 直接依赖 maven
org.apache.kerby:kerb-client 1.0.1 间接依赖 maven
oro:oro 2.0.8 间接依赖 maven
org.apache.hadoop:hadoop-client-runtime 3.3.2 间接依赖 maven
org.apache.kerby:token-provider 1.0.1 间接依赖 maven
com.rabbitmq:amqp-client 5.20.0 间接依赖 maven
net.java.dev.jna:jna 5.13.0 直接依赖 maven
junit:junit 4.13.2 间接依赖 maven
mkdocs 1.5.3 间接依赖 pip
org.apache.hadoop:hadoop-auth 3.3.6 间接依赖 maven
org.glassfish.jersey.core:jersey-server 2.36 间接依赖 maven
org.spark-project.spark:unused 1.0.0 间接依赖 maven
com.google.j2objc:j2objc-annotations 2.8 间接依赖 maven
org.apache.hadoop:hadoop-mapreduce-client-common 3.3.6 间接依赖 maven
jakarta.servlet:jakarta.servlet-api 4.0.3 间接依赖 maven
org.apache.commons:commons-crypto 1.1.0 间接依赖 maven
com.google.code.findbugs:jsr305 3.0.2 直接依赖 maven
io.netty:netty-all 4.1.101.Final 间接依赖 maven
org.apache.avro:avro-mapred 1.11.0 间接依赖 maven
org.apache.zookeeper:zookeeper 3.9.1 间接依赖 maven
org.javatuples:javatuples 1.2 间接依赖 maven
io.cucumber:docstring 6.11.0 间接依赖 maven
com.google.api.grpc:proto-google-common-protos 2.22.0 间接依赖 maven
org.junit.platform:junit-platform-commons 1.10.0 间接依赖 maven
requirements.txt 间接依赖 pip
org.apache.commons:commons-exec 1.3 直接依赖 maven
org.slf4j:jcl-over-slf4j 1.7.36 间接依赖 maven
org.apache.hadoop.thirdparty:hadoop-shaded-protobuf_3_7 1.1.1 间接依赖 maven
org.eclipse.jetty.websocket:websocket-client 9.4.51.v20230217 间接依赖 maven
org.apache.tinkerpop:gremlin-driver 3.7.0 直接依赖 maven
io.netty:netty-transport-rxtx 4.1.101.Final 间接依赖 maven
org.opentest4j:opentest4j 1.3.0 间接依赖 maven
com.ning:compress-lzf 1.1 间接依赖 maven
com.github.jnr:jnr-constants 0.10.3 间接依赖 maven
org.apache.httpcomponents:httpcore-nio 4.4.16 间接依赖 maven
io.opentelemetry:opentelemetry-semconv 1.15.0-alpha 间接依赖 maven
mkdocs-material 9.4.8 间接依赖 pip
com.google.guava:failureaccess 1.0.1 间接依赖 maven
org.apache.hadoop:hadoop-yarn-common 3.3.6 间接依赖 maven
org.apache.kerby:kerby-xdr 1.0.1 间接依赖 maven
org.apache.hadoop:hadoop-hdfs-client 3.3.6 间接依赖 maven
org.apache.logging.log4j:log4j-core 2.20.0 直接依赖 maven
io.cucumber:html-formatter 13.0.0 间接依赖 maven
org.abego.treelayout:org.abego.treelayout.core 1.0.3 间接依赖 maven
com.datastax.oss:java-driver-core 4.17.0 直接依赖 maven
io.netty:netty-codec-socks 4.1.101.Final 间接依赖 maven
io.netty:netty-codec-xml 4.1.101.Final 间接依赖 maven
org.janusgraph:scylla-hadoop-util 1.1.0-SNAPSHOT 直接依赖 maven
org.apache.xbean:xbean-asm9-shaded 4.20 间接依赖 maven
com.thoughtworks.paranamer:paranamer 2.8 间接依赖 maven
org.apache.zookeeper:zookeeper-jute 3.9.1 间接依赖 maven
net.objecthunter:exp4j 0.4.8 间接依赖 maven
com.github.spotbugs:spotbugs-annotations 3.1.12 间接依赖 maven
org.scala-lang:scala-reflect 2.12.15 间接依赖 maven
org.mockito:mockito-junit-jupiter 4.11.0 直接依赖 maven
com.datastax.cassandra:cassandra-driver-core 3.11.5 直接依赖 maven
io.netty:netty-transport-native-unix-common 4.1.101.Final 间接依赖 maven
org.eclipse.jetty:jetty-security 9.4.53.v20231009 间接依赖 maven
org.checkerframework:checker-qual 3.39.0 间接依赖 maven
io.vavr:vavr-match 0.10.4 间接依赖 maven
org.apache.logging.log4j:log4j-1.2-api 2.20.0 直接依赖 maven
org.apache.avro:avro 1.11.3 间接依赖 maven
com.datastax.oss:native-protocol 1.5.1 间接依赖 maven
javax.activation:javax.activation-api 1.2.0 间接依赖 maven
org.apache.httpcomponents:httpasyncclient 4.1.5 间接依赖 maven
org.apache.kerby:kerb-admin 1.0.1 间接依赖 maven
org.json4s:json4s-ast_2.12 3.7.0-M11 间接依赖 maven
javax.activation:activation 1.1.1 间接依赖 maven
org.janusgraph:janusgraph-grpc 1.1.0-SNAPSHOT 直接依赖 maven
org.objenesis:objenesis 3.3 间接依赖 maven
org.jline:jline 3.9.0 间接依赖 maven
io.sgr:s2-geometry-library-java 1.0.0 间接依赖 maven
org.apache.kerby:kerby-util 1.0.1 间接依赖 maven
org.apache.groovy:groovy-templates 4.0.9 间接依赖 maven
org.apache.curator:curator-framework 5.5.0 间接依赖 maven
com.google.errorprone:error_prone_annotations 2.23.0 间接依赖 maven
ch.qos.reload4j:reload4j 1.2.19 间接依赖 maven
com.sun.jersey:jersey-core 1.19.4 间接依赖 maven
org.slf4j:jul-to-slf4j 1.7.32 间接依赖 maven
io.netty:netty-codec-stomp 4.1.101.Final 间接依赖 maven
org.eclipse.jetty.http2:http2-common 9.4.44.v20210927 间接依赖 maven
org.apache.tinkerpop:gremlin-language 3.7.0 间接依赖 maven
com.nimbusds:nimbus-jose-jwt 9.37 间接依赖 maven
org.apache.lucene:lucene-spatial3d 8.11.2 间接依赖 maven
org.awaitility:awaitility 4.0.3 间接依赖 maven
org.javassist:javassist 3.29.2-GA 间接依赖 maven
com.sleepycat:je 18.3.12 直接依赖 maven
org.eclipse.jetty.http2:http2-http-client-transport 9.4.44.v20210927 间接依赖 maven
io.cucumber:cucumber-gherkin 6.11.0 间接依赖 maven
com.github.jnr:jnr-x86asm 1.0.2 间接依赖 maven
com.scylladb:scylla-driver-core 3.11.2.4 直接依赖 maven
org.easymock:easymock 5.2.0 直接依赖 maven
io.netty:netty-buffer 4.1.101.Final 间接依赖 maven
commons-logging:commons-logging 1.2 间接依赖 maven
org.apache.tinkerpop:gremlin-core 3.7.0 直接依赖 maven
org.apache.hbase:hbase-shaded-mapreduce 2.5.6-hadoop3 直接依赖 maven
org.apache.lucene:lucene-backward-codecs 8.11.2 直接依赖 maven
org.apache.groovy:groovy-cli-picocli 4.0.9 间接依赖 maven
io.netty:netty-codec-dns 4.1.101.Final 间接依赖 maven
commons-lang:commons-lang 2.6 间接依赖 maven
org.janusgraph:janusgraph-lucene 1.1.0-SNAPSHOT 直接依赖 maven
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml 2.8.11 间接依赖 maven
org.hdrhistogram:HdrHistogram 2.1.12 间接依赖 maven
io.cucumber:cucumber-guice 6.11.0 间接依赖 maven
org.apache.commons:commons-configuration2 2.9.0 直接依赖 maven
org.apache.commons:commons-math3 3.6.1 间接依赖 maven
io.opentelemetry:opentelemetry-context 1.15.0 间接依赖 maven
io.netty:netty-tcnative-classes 2.0.61.Final 间接依赖 maven
org.junit.vintage:junit-vintage-engine 5.10.0 直接依赖 maven
io.netty:netty-transport 4.1.101.Final 间接依赖 maven
org.roaringbitmap:shims 0.9.25 间接依赖 maven
org.apache.groovy:groovy-swing 4.0.9 间接依赖 maven
org.apache.curator:curator-recipes 5.5.0 间接依赖 maven
io.grpc:grpc-core 1.59.0 直接依赖 maven
com.squareup.okhttp3:okhttp 4.9.3 间接依赖 maven
io.perfmark:perfmark-api 0.26.0 间接依赖 maven
(0)
上一篇 2023年11月29日
下一篇 2023年11月29日

相关推荐

  • mdx-js/mdx 软件分析报告

    基础信息 项目名称:mdx-js/mdx 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1763176230873112576/1763176326008315905 此报告由Murphysec提供 漏洞列表 暂无…

    软件分析 2024年2月29日
    0
  • dodola/WeexOne 软件分析报告

    基础信息 项目名称:dodola/WeexOne 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1717212517968429056/1717212518014566400 此报告由Murphysec提供 漏洞列…

    软件分析 2023年10月26日
    0
  • yangchong211/YCWebView 软件分析报告

    基础信息 项目名称:yangchong211/YCWebView 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1729917591449198592/1729917591826685952 此报告由Murphys…

    软件分析 2023年11月30日
    0
  • fonoster/fonos 软件分析报告

    基础信息 项目名称:fonoster/fonos 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721205825195806720/1726250666963193856 此报告由Murphysec提供 漏洞列…

    软件分析 2023年11月19日
    0
  • bill2candy/GGSDoc 软件分析报告

    基础信息 项目名称:bill2candy/GGSDoc 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1727526404142620672/1727526404851458048 此报告由Murphysec提供 …

    软件分析 2023年11月23日
    0