基础信息
项目名称:jitsi/jitsi
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1719158808768200704/1744023918489821184
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Quality Open Software Logback 安全漏洞 | MPS-n41z-dwb8 | CVE-2023-6481 | 高危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
ch.qos.logback:logback-core | 1.4.12 | 1.4.14 | 间接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 69 | 低 |
LGPL-2.1-or-later | 3 | 低 |
自定义许可证 | 10 | 低 |
GPLv2 | 1 | 中 |
BSD-3-Clause | 6 | 低 |
MIT | 5 | 低 |
LGPL-2.1-only | 2 | 低 |
LGPL-2.1 | 3 | 中 |
MPL-1.1 | 1 | 低 |
EPL-1.0 | 2 | 低 |
EPL-2.0 | 1 | 低 |
WTFPL | 1 | 低 |
GPL-3.0-or-later WITH Classpath-exception-2.0 | 1 | 低 |
LGPL-3.0-or-later | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
org.jitsi.desktop:jitsi-neomedia | 2.14-SNAPSHOT | 直接依赖 | maven |
org.opentelecoms.sdp:java-sdp-nist-bridge | 1.2 | 直接依赖 | maven |
org.jitsi:fmj | 1.0.2-jitsi | 间接依赖 | maven |
com.googlecode.libphonenumber:libphonenumber | 8.13.17 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-propertieseditor | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-contactsource | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-msofficecomm | 2.14-SNAPSHOT | 直接依赖 | maven |
org.apache.commons:commons-compress | 1.24.0 | 直接依赖 | maven |
org.opentelecoms.sdp:sdp-api | 1.0 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-dns | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-usersearch | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.jnr:jffi | 1.3.9 | 间接依赖 | maven |
org.jxmpp:jxmpp-core | 1.0.3 | 直接依赖 | maven |
org.jitsi.desktop:service-provisioning | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jitsi-android-osgi | 2.0-3-gd59644a | 直接依赖 | maven |
org.jitsi:jain-sip-ri-ossonly | 1.2.279-jitsi-oss1 | 直接依赖 | maven |
org.igniterealtime.smack:smack-xmlparser-stax | 4.4.6 | 直接依赖 | maven |
org.apache.commons:commons-lang3 | 3.12.0 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-reconnect | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-provdisc-mdns | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-notificationconfiguration | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-galagonotification | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.jnr:jnr-ffi | 2.2.11 | 间接依赖 | maven |
org.hsqldb:hsqldb | 2.7.2 | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-jdk7 | 1.6.21 | 间接依赖 | maven |
busybox | 间接依赖 | ||
org.jitsi.desktop:jitsi-update | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-irccommands | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-demuxcontactsource | 2.14-SNAPSHOT | 直接依赖 | maven |
org.ow2.asm:asm-util | 9.2 | 间接依赖 | maven |
net.java.dev.jna:jna-platform | 5.13.0 | 直接依赖 | maven |
com.google.guava:failureaccess | 1.0.1 | 间接依赖 | maven |
:No dependencies | 直接依赖 | maven | |
org.jitsi.desktop:jitsi-contactlist | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-common | 1.6.21 | 间接依赖 | maven |
org.jitsi:ice4j | 3.0-62-ga947919 | 直接依赖 | maven |
org.jitsi.desktop:service-filehistory | 2.14-SNAPSHOT | 直接依赖 | maven |
org.opentelecoms.sip:sip-api-1.2 | 1.2 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-busylampfield | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.hypfvieh:dbus-java | 3.3.2 | 直接依赖 | maven |
org.jitsi.desktop:service-globaldisplaydetails | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-metahistory | 2.14-SNAPSHOT | 直接依赖 | maven |
org.igniterealtime.jbosh:jbosh | 0.9.2 | 直接依赖 | maven |
org.ow2.asm:asm | 9.2 | 间接依赖 | maven |
org.osgi:org.osgi.service.cm | 1.6.1 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-contactinfo | 2.14-SNAPSHOT | 直接依赖 | maven |
org.ow2.asm:asm-analysis | 9.2 | 间接依赖 | maven |
org.apache.commons:commons-text | 1.10.0 | 直接依赖 | maven |
org.jitsi:jmyspell-core | 1.0-jitsi-1 | 直接依赖 | maven |
org.igniterealtime.smack:smack-experimental | 4.4.6 | 直接依赖 | maven |
org.jitsi.desktop:service-dnsservice | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-contactsourceconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.javassist:javassist | 3.28.0-GA | 间接依赖 | maven |
commons-io:commons-io | 2.11.0 | 间接依赖 | maven |
org.igniterealtime.smack:smack-xmlparser | 4.4.6 | 间接依赖 | maven |
org.jitsi.desktop:service-systray-service | 2.14-SNAPSHOT | 直接依赖 | maven |
com.google.guava:guava | 32.1.1-jre | 直接依赖 | maven |
org.jitsi.desktop:jitsi-sipaccregwizz | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-defaultresourcepack | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-spellcheck | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-resourcemanager | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-callhistory | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-calendar | 2.14-SNAPSHOT | 直接依赖 | maven |
dnsjava:dnsjava | 3.5.2 | 直接依赖 | maven |
org.jitsi:org.otr4j | 0.23 | 直接依赖 | maven |
org.jitsi:jitsi-utils | 1.0-126-g02b0c86 | 直接依赖 | maven |
com.github.jnr:jnr-a64asm | 1.0.0 | 间接依赖 | maven |
com.github.jnr:jnr-constants | 0.10.3 | 间接依赖 | maven |
org.jetbrains:annotations | 13.0 | 间接依赖 | maven |
org.jitsi.desktop:service-notification-service | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-generalconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-customavatar | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jmork | 1.0.6 | 直接依赖 | maven |
org.jitsi.desktop:service-desktop | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.jnr:jnr-x86asm | 1.0.2 | 间接依赖 | maven |
org.jitsi.desktop:service-ldap | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-protocol | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-packetlogging | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-protocol-jabber | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-connectioninfo | 2.14-SNAPSHOT | 直接依赖 | maven |
org.bouncycastle:bctls-jdk18on | 1.75 | 间接依赖 | maven |
com.helger:dhcp4java | 1.1.0 | 直接依赖 | maven |
org.jitsi.desktop:service-provdisc | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-httputil | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-desktoputil | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:irc-api | 1.0-0015-jitsi-1 | 直接依赖 | maven |
com.github.jnr:jnr-enxio | 0.32.13 | 间接依赖 | maven |
commons-logging:commons-logging | 1.2 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-securityconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-reflect | 1.6.21 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-advancedconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.apache.httpcomponents:httpclient | 4.5.14 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-version | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-muc | 2.14-SNAPSHOT | 直接依赖 | maven |
commons-codec:commons-codec | 1.16.0 | 直接依赖 | maven |
org.bouncycastle:bcpkix-jdk18on | 1.75 | 直接依赖 | maven |
org.jitsi.desktop:service-msghistory | 2.14-SNAPSHOT | 直接依赖 | maven |
org.hsluv:hsluv | 0.2 | 间接依赖 | maven |
ch.imvs:sdes4j | 1.1.5 | 间接依赖 | maven |
org.jitsi.desktop:service-protocol-media | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-protocol-mock | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-customcontactactions | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jicoco-config | 1.1-104-g20c4353 | 间接依赖 | maven |
org.jitsi.desktop:service-certificate | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-notificationwiring | 2.14-SNAPSHOT | 直接依赖 | maven |
org.igniterealtime.smack:smack-bosh | 4.4.6 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-chatalerter | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-googletalkaccregwizz | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-ircaccregwizz | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-chatconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-ldapconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.osgi:osgi.core | 8.0.0 | 直接依赖 | maven |
org.apache.httpcomponents:fluent-hc | 4.5.14 | 直接依赖 | maven |
org.bouncycastle:bcutil-jdk18on | 1.75 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-nimbuzzavatars | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-notification | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jitsi-srtp | 1.1-13-g1d0db60 | 间接依赖 | maven |
ch.qos.logback:logback-core | 1.4.12 | 间接依赖 | maven |
org.jitsi.desktop:service-replacement | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-gui | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.jnr:jnr-posix | 3.1.15 | 间接依赖 | maven |
org.igniterealtime.smack:smack-java8 | 4.4.6 | 间接依赖 | maven |
org.jitsi.desktop:service-browserlauncher | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-util | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-protocol-sip | 2.14-SNAPSHOT | 直接依赖 | maven |
org.reflections:reflections | 0.10.2 | 直接依赖 | maven |
org.bouncycastle:bcprov-jdk18on | 1.75 | 直接依赖 | maven |
org.jitsi:zrtp4j-light | 4.1.3 | 间接依赖 | maven |
com.google.code.findbugs:jsr305 | 3.0.2 | 间接依赖 | maven |
org.igniterealtime.smack:smack-resolver-dnsjava | 4.4.6 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-addrbook | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-credentialsstorage | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-contacteventhandler | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jmdns:jmdns | 3.5.8 | 直接依赖 | maven |
org.igniterealtime.smack:smack-legacy | 4.4.6 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-replacement | 2.14-SNAPSHOT | 直接依赖 | maven |
org.ow2.asm:asm-commons | 9.2 | 间接依赖 | maven |
org.slf4j:log4j-over-slf4j | 2.0.7 | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib | 1.6.21 | 间接依赖 | maven |
org.bitlet:weupnp | 0.1.4 | 间接依赖 | maven |
org.igniterealtime.smack:smack-core | 4.4.6 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-provdisc-dhcp | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-osgi-util | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-branding | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-loggingutils | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-hid | 2.14-SNAPSHOT | 直接依赖 | maven |
net.java.dev.jna:jna | 5.13.0 | 直接依赖 | maven |
org.slf4j:jul-to-slf4j | 2.0.7 | 直接依赖 | maven |
org.igniterealtime.smack:smack-extensions | 4.4.6 | 直接依赖 | maven |
org.jitsi:jitsi-xmpp-extensions | 1.0-72-gc9dde6c | 直接依赖 | maven |
org.jxmpp:jxmpp-util-cache | 1.0.3 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-phonenumbers | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-thunderbird | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-keybindings | 2.14-SNAPSHOT | 直接依赖 | maven |
com.github.jnr:jnr-unixsocket | 0.38.17 | 间接依赖 | maven |
com.typesafe:config | 1.4.1 | 间接依赖 | maven |
org.jitsi.desktop:service-history | 2.14-SNAPSHOT | 直接依赖 | maven |
org.osgi:org.osgi.namespace.implementation | 1.0.0 | 间接依赖 | maven |
org.jitsi:libjitsi | 1.1-32-g2a5a8171 | 直接依赖 | maven |
org.igniterealtime.smack:smack-streammanagement | 4.4.6 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-swingnotification | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-muc | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-dnsconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jitsi-lgpl-dependencies | 1.2-23-g7b49874 | 直接依赖 | maven |
xpp3:xpp3 | 1.1.4c | 间接依赖 | maven |
com.googlecode.json-simple:json-simple | 1.1.1 | 直接依赖 | maven |
org.osgi:osgi.annotation | 8.0.1 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-otr | 2.14-SNAPSHOT | 直接依赖 | maven |
org.igniterealtime.smack:smack-tcp | 4.4.6 | 直接依赖 | maven |
org.igniterealtime.smack:smack-im | 4.4.6 | 直接依赖 | maven |
org.igniterealtime.smack:smack-sasl-javax | 4.4.6 | 直接依赖 | maven |
org.ow2.asm:asm-tree | 9.2 | 间接依赖 | maven |
org.apache.httpcomponents:httpcore | 4.4.16 | 直接依赖 | maven |
org.jxmpp:jxmpp-jid | 1.0.3 | 直接依赖 | maven |
org.jitsi.desktop:service-sysactivity | 2.14-SNAPSHOT | 直接依赖 | maven |
org.minidns:minidns-core | 1.0.4 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-protocol-irc | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jitsi-metaconfig | 1.0-9-g5e1b624 | 间接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-jdk8 | 1.6.21 | 间接依赖 | maven |
org.jitsi.desktop:jitsi-hid | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-contactlist | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-singlecallpolicy | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-accountinfo | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-jabberaccregwizz | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-ui-service | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-pluginmanager | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi:jnsapi | 0.0.3-jitsi-smack4.4-2 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-configuration | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-globalshortcut | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:service-argdelegation | 2.14-SNAPSHOT | 直接依赖 | maven |
org.igniterealtime.smack:smack-debug | 4.4.6 | 直接依赖 | maven |
org.apache.httpcomponents:httpmime | 4.5.14 | 直接依赖 | maven |
org.jitsi.desktop:service-netaddr | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-keybindingchooser | 2.14-SNAPSHOT | 直接依赖 | maven |
org.slf4j:jcl-over-slf4j | 2.0.7 | 直接依赖 | maven |
org.jitsi.desktop:jitsi-globalproxyconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-phonenumbercontactsource | 2.14-SNAPSHOT | 直接依赖 | maven |
org.jitsi.desktop:jitsi-certconfig | 2.14-SNAPSHOT | 直接依赖 | maven |
ch.qos.logback:logback-classic | 1.4.12 | 直接依赖 | maven |
org.slf4j:slf4j-api | 2.0.7 | 直接依赖 | maven |