基础信息
项目名称:apache/opennlp
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1731773026822737920/1731773031042207744
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
【存在争议】FasterXML jackson-databind 代码问题漏洞 | 不加限制或调节的资源分配 | MPS-z1bx-p8y2 | CVE-2023-35116 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
com.fasterxml.jackson.core:jackson-databind | 2.14.1 | 间接依赖 | 建议修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
MIT | 6 | 低 |
Apache-2.0 | 24 | 低 |
EPL-2.0 | 13 | 低 |
自定义许可证 | 11 | 低 |
BSD-2-Clause | 3 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
com.microsoft.onnxruntime:onnxruntime | 1.15.0 | 直接依赖 | maven |
org.apache.logging.log4j:log4j-core | 2.20.0 | 间接依赖 | maven |
org.glassfish.jersey.ext:jersey-entity-filtering | 2.39.1 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-databind | 2.14.1 | 间接依赖 | maven |
com.carrotsearch:hppc | 0.7.2 | 间接依赖 | maven |
org.apache.opennlp:opennlp-brat-annotator | 2.3.2-SNAPSHOT | 直接依赖 | maven |
org.glassfish.jersey.core:jersey-client | 2.39.1 | 间接依赖 | maven |
com.beust:jcommander | 1.78 | 间接依赖 | maven |
jakarta.annotation:jakarta.annotation-api | 1.3.5 | 间接依赖 | maven |
org.glassfish.hk2.external:jakarta.inject | 2.6.1 | 间接依赖 | maven |
org.apache.opennlp:opennlp-morfologik-addon | 2.3.2-SNAPSHOT | 直接依赖 | maven |
org.carrot2:morfologik-stemming | 2.1.9 | 直接依赖 | maven |
org.glassfish.jersey.core:jersey-server | 2.39.1 | 间接依赖 | maven |
jakarta.validation:jakarta.validation-api | 2.0.2 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-core | 2.15.3 | 间接依赖 | maven |
org.glassfish.jersey.core:jersey-common | 2.39.1 | 间接依赖 | maven |
org.carrot2:morfologik-fsa-builders | 2.1.9 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-annotations | 2.15.3 | 间接依赖 | maven |
org.apache.logging.log4j:log4j-slf4j-impl | 2.20.0 | 直接依赖 | maven |
com.fasterxml.jackson.module:jackson-module-jaxb-annotations | 2.14.1 | 间接依赖 | maven |
org.glassfish.jersey.media:jersey-media-json-jackson | 2.39.1 | 直接依赖 | maven |
org.glassfish.grizzly:grizzly-http | 2.4.4 | 间接依赖 | maven |
org.slf4j:slf4j-api | 1.7.36 | 直接依赖 | maven |
com.fasterxml.jackson.core:jackson-annotations | 2.14.1 | 间接依赖 | maven |
org.glassfish.hk2:osgi-resource-locator | 1.0.3 | 间接依赖 | maven |
org.glassfish.grizzly:grizzly-framework | 2.4.4 | 间接依赖 | maven |
org.apache.logging.log4j:log4j-api | 2.20.0 | 间接依赖 | maven |
org.carrot2:morfologik-fsa | 2.1.9 | 间接依赖 | maven |
jakarta.ws.rs:jakarta.ws.rs-api | 2.1.6 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-core | 2.14.1 | 间接依赖 | maven |
org.glassfish.jersey.containers:jersey-container-grizzly2-http | 2.39.1 | 直接依赖 | maven |
org.apache.opennlp:opennlp-dl | 2.3.2-SNAPSHOT | 直接依赖 | maven |
com.fasterxml.jackson.core:jackson-databind | 2.15.3 | 直接依赖 | maven |
org.apache.opennlp:opennlp-uima | 2.3.2-SNAPSHOT | 直接依赖 | maven |
org.glassfish.grizzly:grizzly-http-server | 2.4.4 | 间接依赖 | maven |
jakarta.xml.bind:jakarta.xml.bind-api | 2.3.3 | 间接依赖 | maven |
org.carrot2:morfologik-tools | 2.1.9 | 直接依赖 | maven |
com.microsoft.onnxruntime:onnxruntime_gpu | 1.15.0 | 直接依赖 | maven |
org.apache.opennlp:opennlp-tools | 2.3.2-SNAPSHOT | 直接依赖 | maven |