基础信息
项目名称:LWJGL/lwjgl3-www
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1744529747334897664/1744529747708190721
此报告由Murphysec提供
漏洞列表
| 漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
|---|---|---|---|---|
| CVE-2023-51701漏洞 | HTTP请求走私 | MPS-s6j1-5zh8 | CVE-2023-51701 | 中危 |
缺陷组件
| 组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
|---|---|---|---|---|
| @fastify/reply-from | 9.4.0 | 9.6.0 | 间接依赖 | 可选修复 |
许可证风险
| 许可证类型 | 相关组件 | 许可证风险 |
|---|---|---|
| MIT | 125 | 低 |
| ISC | 12 | 低 |
| Apache-2.0 | 36 | 低 |
| 0BSD | 2 | 低 |
| BSD-3-Clause | 4 | 低 |
| BSD-2-Clause | 1 | 低 |
SBOM清单
| 组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
|---|---|---|---|
| fast-xml-parser | 4.2.5 | 间接依赖 | npm |
| readable-stream | 4.4.2 | 间接依赖 | npm |
| pug-code-gen | 3.0.2 | 间接依赖 | npm |
| strnum | 1.0.5 | 间接依赖 | npm |
| function-bind | 1.1.2 | 间接依赖 | npm |
| hasown | 2.0.0 | 间接依赖 | npm |
| @fastify/accepts | 4.2.0 | 间接依赖 | npm |
| safe-stable-stringify | 2.4.3 | 间接依赖 | npm |
| find-my-way | 7.7.0 | 间接依赖 | npm |
| real-require | 0.2.0 | 间接依赖 | npm |
| fast-decode-uri-component | 1.0.1 | 间接依赖 | npm |
| @smithy/eventstream-serde-browser | 2.0.12 | 间接依赖 | npm |
| object-assign | 4.1.1 | 间接依赖 | npm |
| @smithy/util-defaults-mode-browser | 2.0.16 | 间接依赖 | npm |
| debug | 4.3.4 | 间接依赖 | npm |
| @smithy/querystring-builder | 2.0.12 | 间接依赖 | npm |
| inflight | 1.0.6 | 间接依赖 | npm |
| toad-cache | 3.3.0 | 间接依赖 | npm |
| @babel/helper-validator-identifier | 7.22.20 | 间接依赖 | npm |
| rfdc | 1.3.0 | 间接依赖 | npm |
| is-core-module | 2.13.1 | 间接依赖 | npm |
| @smithy/hash-node | 2.0.12 | 间接依赖 | npm |
| @smithy/fetch-http-handler | 2.2.4 | 间接依赖 | npm |
| @smithy/middleware-stack | 2.0.6 | 间接依赖 | npm |
| fastify | 4.24.3 | 间接依赖 | npm |
| @fastify/error | 3.4.1 | 间接依赖 | npm |
| @smithy/abort-controller | 2.0.12 | 间接依赖 | npm |
| acorn | 7.4.1 | 间接依赖 | npm |
| @aws-crypto/crc32 | 3.0.0 | 间接依赖 | npm |
| @smithy/util-utf8 | 2.0.2 | 间接依赖 | npm |
| @fastify/fast-json-stringify-compiler | 4.3.0 | 间接依赖 | npm |
| @smithy/middleware-content-length | 2.0.14 | 间接依赖 | npm |
| @smithy/util-defaults-mode-node | 2.0.22 | 间接依赖 | npm |
| minimatch | 9.0.3 | 间接依赖 | npm |
| wrappy | 1.0.2 | 间接依赖 | npm |
| once | 1.4.0 | 间接依赖 | npm |
| @smithy/credential-provider-imds | 2.1.0 | 间接依赖 | npm |
| token-stream | 1.0.0 | 间接依赖 | npm |
| @aws-sdk/credential-provider-node | 3.449.0 | 间接依赖 | npm |
| pug-runtime | 3.0.1 | 间接依赖 | npm |
| minimatch | 5.1.6 | 间接依赖 | npm |
| @smithy/hash-stream-node | 2.0.12 | 间接依赖 | npm |
| process | 0.11.10 | 间接依赖 | npm |
| constantinople | 4.0.1 | 间接依赖 | npm |
| @aws-sdk/credential-provider-sso | 3.449.0 | 间接依赖 | npm |
| proxy-addr | 2.0.7 | 间接依赖 | npm |
| inherits | 2.0.4 | 间接依赖 | npm |
| @smithy/shared-ini-file-loader | 2.2.3 | 间接依赖 | npm |
| forwarded | 0.2.0 | 间接依赖 | npm |
| @smithy/util-base64 | 2.0.0 | 间接依赖 | npm |
| pug-filters | 4.0.0 | 间接依赖 | npm |
| fast-redact | 3.3.0 | 间接依赖 | npm |
| pump | 3.0.0 | 间接依赖 | npm |
| content-disposition | 0.5.4 | 间接依赖 | npm |
| @smithy/util-hex-encoding | 2.0.0 | 间接依赖 | npm |
| @smithy/util-uri-escape | 2.0.0 | 间接依赖 | npm |
| resolve | 1.22.8 | 间接依赖 | npm |
| assert-never | 1.2.1 | 间接依赖 | npm |
| mime-db | 1.52.0 | 间接依赖 | npm |
| @aws-sdk/util-user-agent-node | 3.449.0 | 间接依赖 | npm |
| gopd | 1.0.1 | 间接依赖 | npm |
| @smithy/protocol-http | 3.0.8 | 间接依赖 | npm |
| @aws-sdk/middleware-logger | 3.449.0 | 间接依赖 | npm |
| @smithy/util-body-length-node | 2.1.0 | 间接依赖 | npm |
| negotiator | 0.6.3 | 间接依赖 | npm |
| get-intrinsic | 1.2.2 | 间接依赖 | npm |
| split2 | 4.2.0 | 间接依赖 | npm |
| @smithy/querystring-parser | 2.0.12 | 间接依赖 | npm |
| @aws-sdk/credential-provider-process | 3.449.0 | 间接依赖 | npm |
| fast-json-stringify | 5.9.1 | 间接依赖 | npm |
| @aws-sdk/util-user-agent-browser | 3.449.0 | 间接依赖 | npm |
| safe-buffer | 5.2.1 | 间接依赖 | npm |
| event-target-shim | 5.0.1 | 间接依赖 | npm |
| sonic-boom | 3.7.0 | 间接依赖 | npm |
| pug | 3.0.2 | 间接依赖 | npm |
| is-regex | 1.1.4 | 间接依赖 | npm |
| js-stringify | 1.0.2 | 间接依赖 | npm |
| @fastify/ajv-compiler | 3.5.0 | 间接依赖 | npm |
| glob | 8.1.0 | 间接依赖 | npm |
| @aws-sdk/credential-provider-ini | 3.449.0 | 间接依赖 | npm |
| pug-lexer | 5.0.1 | 间接依赖 | npm |
| @aws-sdk/middleware-location-constraint | 3.449.0 | 间接依赖 | npm |
| @smithy/md5-js | 2.0.12 | 间接依赖 | npm |
| @fastify/reply-from | 9.4.0 | 间接依赖 | npm |
| @smithy/service-error-classification | 2.0.5 | 间接依赖 | npm |
| process-warning | 2.3.0 | 间接依赖 | npm |
| jstransformer | 1.0.0 | 间接依赖 | npm |
| fast-querystring | 1.1.2 | 间接依赖 | npm |
| cookie | 0.5.0 | 间接依赖 | npm |
| to-fast-properties | 2.0.0 | 间接依赖 | npm |
| @smithy/middleware-endpoint | 2.1.4 | 间接依赖 | npm |
| has-property-descriptors | 1.0.1 | 间接依赖 | npm |
| atomic-sleep | 1.0.0 | 间接依赖 | npm |
| @aws-sdk/middleware-bucket-endpoint | 3.449.0 | 间接依赖 | npm |
| fastq | 1.15.0 | 间接依赖 | npm |
| punycode | 2.3.1 | 间接依赖 | npm |
| end-of-stream | 1.4.4 | 间接依赖 | npm |
| tslib | 2.6.2 | 间接依赖 | npm |
| brace-expansion | 2.0.1 | 间接依赖 | npm |
| tslib | 1.14.1 | 间接依赖 | npm |
| ajv-formats | 2.1.1 | 间接依赖 | npm |
| is-promise | 2.2.2 | 间接依赖 | npm |
| @smithy/chunked-blob-reader-native | 2.0.0 | 间接依赖 | npm |
| babel-walk | 3.0.0-canary-5 | 间接依赖 | npm |
| secure-json-parse | 2.7.0 | 间接依赖 | npm |
| @aws-crypto/supports-web-crypto | 3.0.0 | 间接依赖 | npm |
| @aws-sdk/middleware-expect-continue | 3.449.0 | 间接依赖 | npm |
| base64-js | 1.5.1 | 间接依赖 | npm |
| fastify-plugin | 4.5.1 | 间接依赖 | npm |
| balanced-match | 1.0.2 | 间接依赖 | npm |
| tiny-lru | 11.2.5 | 间接依赖 | npm |
| buffer | 6.0.3 | 间接依赖 | npm |
| undici | 5.27.2 | 间接依赖 | npm |
| doctypes | 1.1.0 | 间接依赖 | npm |
| @babel/types | 7.23.3 | 间接依赖 | npm |
| ms | 2.1.2 | 间接依赖 | npm |
| @smithy/types | 2.4.0 | 间接依赖 | npm |
| statuses | 2.0.1 | 间接依赖 | npm |
| has-proto | 1.0.1 | 间接依赖 | npm |
| @aws-sdk/token-providers | 3.449.0 | 间接依赖 | npm |
| @aws-sdk/util-endpoints | 3.449.0 | 间接依赖 | npm |
| reusify | 1.0.4 | 间接依赖 | npm |
| pino | 8.16.1 | 间接依赖 | npm |
| accepts | 1.3.8 | 间接依赖 | npm |
| @aws-sdk/util-locate-window | 3.310.0 | 间接依赖 | npm |
| yocto-queue | 0.1.0 | 间接依赖 | npm |
| @smithy/hash-blob-browser | 2.0.12 | 间接依赖 | npm |
| pug-error | 2.0.0 | 间接依赖 | npm |
| @fastify/view | 8.2.0 | 间接依赖 | npm |
| supports-preserve-symlinks-flag | 1.0.0 | 间接依赖 | npm |
| has-tostringtag | 1.0.0 | 间接依赖 | npm |
| @aws-sdk/xml-builder | 3.310.0 | 间接依赖 | npm |
| fast-uri | 2.3.0 | 间接依赖 | npm |
| @smithy/is-array-buffer | 2.0.0 | 间接依赖 | npm |
| helmet | 7.1.0 | 间接依赖 | npm |
| @aws-sdk/client-sts | 3.449.0 | 间接依赖 | npm |
| has-symbols | 1.0.3 | 间接依赖 | npm |
| escape-html | 1.0.3 | 间接依赖 | npm |
| @smithy/util-body-length-browser | 2.0.0 | 间接依赖 | npm |
| define-data-property | 1.1.1 | 间接依赖 | npm |
| @fastify/static | 6.12.0 | 间接依赖 | npm |
| fs.realpath | 1.0.0 | 间接依赖 | npm |
| @smithy/eventstream-serde-config-resolver | 2.0.12 | 间接依赖 | npm |
| ws | 8.14.2 | 间接依赖 | npm |
| @aws-sdk/util-arn-parser | 3.310.0 | 间接依赖 | npm |
| is-expression | 4.0.0 | 间接依赖 | npm |
| @lukeed/ms | 2.0.1 | 间接依赖 | npm |
| @fastify/accept-negotiator | 1.1.0 | 间接依赖 | npm |
| depd | 2.0.0 | 间接依赖 | npm |
| @aws-sdk/types | 3.449.0 | 间接依赖 | npm |
| @aws-sdk/credential-provider-web-identity | 3.449.0 | 间接依赖 | npm |
| call-bind | 1.0.5 | 间接依赖 | npm |
| pino-std-serializers | 6.2.2 | 间接依赖 | npm |
| @smithy/eventstream-codec | 2.0.12 | 间接依赖 | npm |
| @smithy/chunked-blob-reader | 2.0.0 | 间接依赖 | npm |
| @smithy/util-stream | 2.0.17 | 间接依赖 | npm |
| pug-attrs | 3.0.0 | 间接依赖 | npm |
| pug-walk | 2.0.0 | 间接依赖 | npm |
| @babel/parser | 7.23.3 | 间接依赖 | npm |
| semver | 7.5.4 | 间接依赖 | npm |
| @fastify/send | 2.1.0 | 间接依赖 | npm |
| @aws-sdk/middleware-host-header | 3.449.0 | 间接依赖 | npm |
| p-limit | 3.1.0 | 间接依赖 | npm |
| set-cookie-parser | 2.6.0 | 间接依赖 | npm |
| @aws-sdk/middleware-user-agent | 3.449.0 | 间接依赖 | npm |
| @aws-crypto/sha256-browser | 3.0.0 | 间接依赖 | npm |
| @aws-sdk/util-utf8-browser | 3.259.0 | 间接依赖 | npm |
| with | 7.0.2 | 间接依赖 | npm |
| toidentifier | 1.0.1 | 间接依赖 | npm |
| pug-strip-comments | 2.0.0 | 间接依赖 | npm |
| @aws-sdk/middleware-ssec | 3.449.0 | 间接依赖 | npm |
| hashlru | 2.3.0 | 间接依赖 | npm |
| @aws-crypto/ie11-detection | 3.0.0 | 间接依赖 | npm |
| setprototypeof | 1.2.0 | 间接依赖 | npm |
| quick-format-unescaped | 4.0.4 | 间接依赖 | npm |
| asap | 2.0.6 | 间接依赖 | npm |
| ajv | 8.12.0 | 间接依赖 | npm |
| @smithy/middleware-retry | 2.0.19 | 间接依赖 | npm |
| @smithy/invalid-dependency | 2.0.12 | 间接依赖 | npm |
| abstract-logging | 2.0.1 | 间接依赖 | npm |
| @aws-sdk/core | 3.445.0 | 间接依赖 | npm |
| events | 3.3.0 | 间接依赖 | npm |
| @smithy/eventstream-serde-universal | 2.0.12 | 间接依赖 | npm |
| @aws-crypto/sha1-browser | 3.0.0 | 间接依赖 | npm |
| @aws-sdk/client-sso | 3.449.0 | 间接依赖 | npm |
| pug-parser | 6.0.0 | 间接依赖 | npm |
| @aws-sdk/region-config-resolver | 3.433.0 | 间接依赖 | npm |
| @fastify/busboy | 2.0.0 | 间接依赖 | npm |
| avvio | 8.2.1 | 间接依赖 | npm |
| @fastify/deepmerge | 1.3.0 | 间接依赖 | npm |
| http-errors | 2.0.0 | 间接依赖 | npm |
| @aws-crypto/crc32c | 3.0.0 | 间接依赖 | npm |
| @smithy/util-config-provider | 2.0.0 | 间接依赖 | npm |
| @aws-crypto/sha256-js | 3.0.0 | 间接依赖 | npm |
| @aws-sdk/middleware-sdk-sts | 3.449.0 | 间接依赖 | npm |
| @smithy/eventstream-serde-node | 2.0.12 | 间接依赖 | npm |
| @smithy/util-endpoints | 1.0.3 | 间接依赖 | npm |
| mime | 3.0.0 | 间接依赖 | npm |
| ret | 0.2.2 | 间接依赖 | npm |
| bowser | 2.11.0 | 间接依赖 | npm |
| @aws-crypto/util | 3.0.0 | 间接依赖 | npm |
| @aws-sdk/middleware-signing | 3.449.0 | 间接依赖 | npm |
| uri-js | 4.4.1 | 间接依赖 | npm |
| @aws-sdk/middleware-sdk-s3 | 3.449.0 | 间接依赖 | npm |
| @fastify/http-proxy | 9.3.0 | 间接依赖 | npm |
| @smithy/util-buffer-from | 2.0.0 | 间接依赖 | npm |
| @smithy/node-http-handler | 2.1.8 | 间接依赖 | npm |
| @fastify/helmet | 11.1.1 | 间接依赖 | npm |
| light-my-request | 5.11.0 | 间接依赖 | npm |
| json-schema-ref-resolver | 1.0.1 | 间接依赖 | npm |
| @babel/helper-string-parser | 7.22.5 | 间接依赖 | npm |
| require-from-string | 2.0.2 | 间接依赖 | npm |
| @aws-sdk/middleware-recursion-detection | 3.449.0 | 间接依赖 | npm |
| @aws-sdk/credential-provider-env | 3.449.0 | 间接依赖 | npm |
| uuid | 8.3.2 | 间接依赖 | npm |
| promise | 7.3.1 | 间接依赖 | npm |
| character-parser | 2.2.0 | 间接依赖 | npm |
| pug-linker | 4.0.0 | 间接依赖 | npm |
| @smithy/smithy-client | 2.1.12 | 间接依赖 | npm |
| @fastify/etag | 4.2.0 | 间接依赖 | npm |
| set-function-length | 1.1.1 | 间接依赖 | npm |
| @aws-sdk/client-s3 | 3.449.0 | 间接依赖 | npm |
| fast-deep-equal | 3.1.3 | 间接依赖 | npm |
| @smithy/util-waiter | 2.0.12 | 间接依赖 | npm |
| on-exit-leak-free | 2.1.2 | 间接依赖 | npm |
| @smithy/property-provider | 2.0.13 | 间接依赖 | npm |
| pino-abstract-transport | 1.1.0 | 间接依赖 | npm |
| path-parse | 1.0.7 | 间接依赖 | npm |
| void-elements | 3.1.0 | 间接依赖 | npm |
| thread-stream | 2.4.1 | 间接依赖 | npm |
| safe-regex2 | 2.0.0 | 间接依赖 | npm |
| pug-load | 3.0.0 | 间接依赖 | npm |
| archy | 1.0.0 | 间接依赖 | npm |
| mime-types | 2.1.35 | 间接依赖 | npm |
| abort-controller | 3.0.0 | 间接依赖 | npm |
| @smithy/url-parser | 2.0.12 | 间接依赖 | npm |
| ieee754 | 1.2.1 | 间接依赖 | npm |
| fast-content-type-parse | 1.1.0 | 间接依赖 | npm |
| ipaddr.js | 1.9.1 | 间接依赖 | npm |
| @smithy/util-retry | 2.0.5 | 间接依赖 | npm |
| @aws-sdk/signature-v4-multi-region | 3.449.0 | 间接依赖 | npm |
| @smithy/node-config-provider | 2.1.4 | 间接依赖 | npm |
| @smithy/signature-v4 | 2.0.14 | 间接依赖 | npm |
| @aws-sdk/middleware-flexible-checksums | 3.449.0 | 间接依赖 | npm |
| @smithy/config-resolver | 2.0.17 | 间接依赖 | npm |
| @smithy/util-middleware | 2.0.5 | 间接依赖 | npm |
| @smithy/middleware-serde | 2.0.12 | 间接依赖 | npm |