基础信息
项目名称:apache/openwebbeans
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1730004362543456256/1730004362581204992
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
TestNG | 路径遍历 | MPS-2022-64736 | CVE-2022-4065 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
org.testng:testng | 7.4.0 | 7.7.0 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 67 | 低 |
EPL-2.0 | 5 | 低 |
自定义许可证 | 1 | 低 |
MIT | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
org.apache.openwebbeans:openwebbeans-ejb | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.enterprise:cdi-tck-ext-lib | 4.0.12 | 间接依赖 | maven |
org.jboss.arquillian.test:arquillian-test-api | 1.7.1.Final | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-spi | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-api-javaee | 2.0.0 | 间接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-impl-base | 1.7.1.Final | 直接依赖 | maven |
org.jboss.arquillian.core:arquillian-core-impl-base | 1.7.0.Alpha10 | 间接依赖 | maven |
org.apache.tomcat:tomcat-el-api | 10.1.5 | 间接依赖 | maven |
org.jboss.arquillian.test:arquillian-test-api | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.shrinkwrap:shrinkwrap-spi | 1.2.6 | 间接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-impl-base | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-api | 1.7.1.Final | 间接依赖 | maven |
org.jboss.test-audit:jboss-test-audit-api | 2.0.0.Final | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-se | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.enterprise:cdi-tck-api | 4.0.12 | 直接依赖 | maven |
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-impl-base | 2.0.0 | 间接依赖 | maven |
jakarta.enterprise:jakarta.enterprise.lang-model | 4.0.1 | 间接依赖 | maven |
jakarta.ejb:jakarta.ejb-api | 4.0.1 | 直接依赖 | maven |
org.apache.tomcat:tomcat-jsp-api | 10.1.5 | 直接依赖 | maven |
org.apache.openwebbeans:openwebbeans-el22 | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.inject:jakarta.inject-api | 2.0.1 | 直接依赖 | maven |
org.apache.tomcat:tomcat-jasper-el | 10.1.5 | 直接依赖 | maven |
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-api-base | 2.0.0 | 间接依赖 | maven |
org.jboss.arquillian.container:container-se-api | 1.0.1.Final | 间接依赖 | maven |
org.jboss.arquillian.test:arquillian-test-spi | 1.7.1.Final | 直接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-spi | 1.7.0.Alpha10 | 间接依赖 | maven |
org.apache.tomcat:tomcat-servlet-api | 10.1.5 | 直接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-spi | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-impl-base | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-impl-javaee | 2.0.0 | 间接依赖 | maven |
org.jboss.shrinkwrap:shrinkwrap-api | 1.2.6 | 直接依赖 | maven |
org.jboss.shrinkwrap:shrinkwrap-api | 1.2.2 | 间接依赖 | maven |
jakarta.transaction:jakarta.transaction-api | 2.0.1 | 直接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-spi | 1.7.1.Final | 间接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-test-api | 1.7.0.Alpha10 | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-tomcat | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.el:jakarta.el-api | 4.0.0 | 直接依赖 | maven |
com.beust:jcommander | 1.78 | 间接依赖 | maven |
jakarta.enterprise:jakarta.enterprise.cdi-api | 4.0.1 | 直接依赖 | maven |
org.apache.openwebbeans:openwebbeans-osgi | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.apache.openwebbeans:openwebbeans-jsf | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.interceptor:jakarta.interceptor-api | 2.0.0 | 直接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-spi | 1.7.1.Final | 直接依赖 | maven |
org.jboss.arquillian.core:arquillian-core-api | 1.7.1.Final | 间接依赖 | maven |
org.jboss.test-audit:jboss-test-audit-impl | 2.0.0.Final | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-impl | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.jboss.shrinkwrap:shrinkwrap-impl-base | 1.2.6 | 间接依赖 | maven |
org.jboss.arquillian.core:arquillian-core-spi | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-impl-base | 1.7.1.Final | 间接依赖 | maven |
org.apache.xbean:xbean-finder-shaded | 4.24 | 直接依赖 | maven |
org.apache.openwebbeans:openwebbeans-ee | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-api | 1.7.1.Final | 间接依赖 | maven |
org.jboss.arquillian.testenricher:arquillian-testenricher-cdi-jakarta | 1.7.1.Final | 直接依赖 | maven |
org.jboss.arquillian.testng:arquillian-testng-container | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.test:arquillian-test-impl-base | 1.7.0.Alpha10 | 间接依赖 | maven |
jakarta.enterprise:cdi-tck-core-impl | 4.0.12 | 直接依赖 | maven |
org.jboss.arquillian.test:arquillian-test-spi | 1.7.0.Alpha10 | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-web | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.apache.openwebbeans:openwebbeans-ee-common | 4.0.2-SNAPSHOT | 直接依赖 | maven |
org.apache.openwebbeans.arquillian:owb-arquillian-standalone | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.annotation:jakarta.annotation-api | 2.1.1 | 直接依赖 | maven |
org.jboss.arquillian.testng:arquillian-testng-core | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.container:arquillian-container-impl-base | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-spi | 2.0.0 | 间接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-spi | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.core:arquillian-core-api | 1.7.0.Alpha10 | 间接依赖 | maven |
org.jboss.arquillian.core:arquillian-core-spi | 1.7.1.Final | 间接依赖 | maven |
org.apache.xbean:xbean-asm9-shaded | 4.24 | 直接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-spi | 1.7.1.Final | 间接依赖 | maven |
org.apache.openwebbeans:openwebbeans-jms | 4.0.2-SNAPSHOT | 直接依赖 | maven |
jakarta.validation:jakarta.validation-api | 3.0.2 | 直接依赖 | maven |
org.webjars:jquery | 3.5.1 | 间接依赖 | maven |
org.jboss.arquillian.config:arquillian-config-api | 1.7.0.Alpha10 | 间接依赖 | maven |
org.testng:testng | 7.4.0 | 间接依赖 | maven |
org.apache.myfaces.core:myfaces-api | 4.0.1 | 直接依赖 | maven |