metersphere/metersphere 软件分析报告

基础信息

项目名称:metersphere/metersphere

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1752508655388708864/1755619410144161792

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Apache XML Graphics Batik SSRF MPS-2022-63578 CVE-2022-44729 中危
Apache XML Graphics Batik 代码问题漏洞 SSRF MPS-2022-63579 CVE-2022-44730 中危
Apache Tika 正则表达式拒绝服务漏洞 拒绝服务 MPS-2022-9836 CVE-2022-30126 中危
Jayway JsonPath 安全漏洞 MPS-5f8t-odky CVE-2023-51074 中危
【存在争议】FasterXML jackson-databind 代码问题漏洞 不加限制或调节的资源分配 MPS-z1bx-p8y2 CVE-2023-35116 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
org.apache.xmlgraphics:batik-bridge 1.16 1.17 间接依赖 强烈建议修复
org.apache.xmlgraphics:batik-transcoder 1.16 1.17 间接依赖 强烈建议修复
com.fasterxml.jackson.core:jackson-databind 2.15.3 2.16.0 直接依赖 建议修复
org.apache.tika:tika-core 1.28.5 2.4.1 间接依赖 可选修复
com.jayway.jsonpath:json-path 2.8.0 2.9.0 间接依赖 可选修复
org.apache.xmlgraphics:batik-script 1.16 1.17 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 247
MIT 32
BSD-2-Clause 12
EDL-1.0 7
LGPL-2.1 4
EPL-1.0 24
LGPL-3.0-or-later 8
BSD-3-Clause 11
自定义许可证 3
CDDL-1.1 2
GPL-2.0-with-classpath-exception 5
Plexus 1
LGPL-3.0 1
MIT-0 1
WTFPL 1
GPL-2.0 1
Public-Domain 2
MPL-1.1 1
EPL-2.0 4
Indiana-University-Extreme-Lab-1.2 1
Apache-1.1 1
MPL-2.0 2

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
org.pf4j:pf4j 3.10.0 直接依赖 maven
org.codehaus.groovy:groovy-xml 3.0.20 间接依赖 maven
com.github.weisj:darklaf-extensions-rsyntaxarea 0.3.4 间接依赖 maven
com.google.errorprone:error_prone_annotations 2.21.1 间接依赖 maven
org.mybatis:mybatis 3.5.14 间接依赖 maven
org.lz4:lz4-java 1.8.0 间接依赖 maven
org.jboss.logging:jboss-logging 3.5.3.Final 间接依赖 maven
org.codehaus.groovy:groovy-jmx 3.0.20 间接依赖 maven
org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-server 12.0.5 间接依赖 maven
org.jboss.marshalling:jboss-marshalling 2.0.11.Final 间接依赖 maven
jakarta.websocket:jakarta.websocket-client-api 2.1.1 间接依赖 maven
io.swagger:swagger-compat-spec-parser 1.0.68 间接依赖 maven
org.jodd:jodd-log 5.0.13 间接依赖 maven
org.codehaus.groovy:groovy-templates 3.0.20 间接依赖 maven
org.quartz-scheduler:quartz 2.3.2 间接依赖 maven
org.springframework:spring-context 6.1.3 间接依赖 maven
org.brotli:dec 0.1.2 间接依赖 maven
org.glassfish.jaxb:txw2 4.0.4 间接依赖 maven
org.apache.xmlgraphics:batik-svggen 1.16 间接依赖 maven
org.springframework.boot:spring-boot-starter-websocket 3.2.2 直接依赖 maven
org.springframework.boot:spring-boot-starter-jdbc 3.2.2 间接依赖 maven
com.google.j2objc:j2objc-annotations 2.8 间接依赖 maven
org.apache.httpcomponents:httpasyncclient 4.1.5 间接依赖 maven
org.apache.xmlgraphics:batik-awt-util 1.16 间接依赖 maven
com.mchange:mchange-commons-java 0.2.15 间接依赖 maven
com.github.java-json-tools:uri-template 0.10 间接依赖 maven
org.springframework:spring-tx 6.1.3 间接依赖 maven
com.zaxxer:SparseBitSet 1.2 间接依赖 maven
commons-collections:commons-collections 3.2.2 间接依赖 maven
org.apache.xmlgraphics:batik-script 1.16 间接依赖 maven
com.fit2cloud:quartz-spring-boot-starter 1.0.7 直接依赖 maven
com.github.java-json-tools:json-schema-validator 2.2.14 直接依赖 maven
org.jetbrains.lets-plot:plot-stem-jvm 4.1.0 间接依赖 maven
com.github.java-json-tools:jackson-coreutils-equivalence 1.0 间接依赖 maven
com.aliyun:alibabacloud-gateway-spi 0.0.1 间接依赖 maven
org.springdoc:springdoc-openapi-starter-common 2.3.0 间接依赖 maven
org.apache.httpcomponents.client5:httpclient5 5.2.3 直接依赖 maven
org.redisson:redisson-spring-boot-starter 3.26.0 直接依赖 maven
org.springframework:spring-messaging 6.1.3 间接依赖 maven
net.bytebuddy:byte-buddy 1.14.11 间接依赖 maven
org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-servlet 12.0.5 间接依赖 maven
joda-time:joda-time 2.10.5 间接依赖 maven
io.swagger.parser.v3:swagger-parser-v3 2.1.19 间接依赖 maven
com.googlecode.javaewah:JavaEWAH 1.2.3 间接依赖 maven
org.springframework.session:spring-session-data-redis 3.2.1 直接依赖 maven
com.jayway.jsonpath:json-path 2.8.0 间接依赖 maven
io.reactivex.rxjava3:rxjava 3.1.8 间接依赖 maven
org.apache.jmeter:ApacheJMeter_core 5.6.3 直接依赖 maven
org.checkerframework:checker-qual 3.41.0 间接依赖 maven
org.springdoc:springdoc-openapi-starter-webmvc-api 2.3.0 间接依赖 maven
org.apache.jmeter:ApacheJMeter_http 5.6.3 直接依赖 maven
com.github.virtuald:curvesapi 1.06 间接依赖 maven
org.xmlresolver:xmlresolver 5.2.1 间接依赖 maven
org.jodd:jodd-core 5.0.13 间接依赖 maven
com.fifesoft:rsyntaxtextarea 3.3.4 间接依赖 maven
org.apache.tika:tika-parsers 1.28.5 间接依赖 maven
org.springframework.boot:spring-boot-starter-data-redis 3.2.2 间接依赖 maven
org.hibernate.validator:hibernate-validator 8.0.1.Final 间接依赖 maven
org.owasp.encoder:encoder 1.2.3 间接依赖 maven
com.squareup.okhttp3:okhttp 4.12.0 间接依赖 maven
io.micrometer:micrometer-commons 1.12.2 间接依赖 maven
com.fasterxml.jackson.dataformat:jackson-dataformat-toml 2.15.3 间接依赖 maven
com.github.java-json-tools:json-patch 1.13 间接依赖 maven
com.github.weisj:darklaf-native-utils 2.7.3 间接依赖 maven
xalan:xalan 2.7.3 间接依赖 maven
com.github.java-json-tools:btf 1.3 间接依赖 maven
commons-beanutils:commons-beanutils 1.9.4 间接依赖 maven
com.github.weisj:swing-extensions-laf-support 0.1.3 间接依赖 maven
org.jetbrains.lets-plot:platf-awt-jvm 4.1.0 间接依赖 maven
com.github.pagehelper:pagehelper 6.1.0 直接依赖 maven
com.miglayout:miglayout-core 5.3 间接依赖 maven
org.eclipse.jetty:jetty-client 12.0.5 间接依赖 maven
org.apache.xmlgraphics:batik-dom 1.16 间接依赖 maven
org.eclipse.jetty:jetty-security 12.0.5 间接依赖 maven
com.zaxxer:HikariCP 5.0.1 间接依赖 maven
org.jetbrains.kotlinx:kotlinx-coroutines-core 1.7.3 间接依赖 maven
com.sun.activation:javax.activation 1.2.0 间接依赖 maven
org.springframework:spring-context-support 6.1.3 间接依赖 maven
org.jetbrains.lets-plot:plot-builder-jvm 4.1.0 间接依赖 maven
com.alibaba:easyexcel-support 3.3.3 间接依赖 maven
com.aliyun:endpoint-util 0.0.7 间接依赖 maven
org.apache.xmlgraphics:batik-parser 1.16 间接依赖 maven
com.github.weisj:darklaf-windows 2.7.3 间接依赖 maven
org.apache.commons:commons-csv 1.8 间接依赖 maven
org.jetbrains.kotlinx:kotlinx-coroutines-core-jvm 1.7.3 间接依赖 maven
org.apache.tomcat.embed:tomcat-embed-el 10.1.18 间接依赖 maven
org.eclipse.jetty:jetty-session 12.0.5 间接依赖 maven
io.netty:netty-resolver-dns 4.1.105.Final 间接依赖 maven
org.apache.httpcomponents:httpcore-nio 4.4.16 间接依赖 maven
io.metersphere:metersphere-load-test 3.x 直接依赖 maven
org.dom4j:dom4j 2.1.4 直接依赖 maven
org.apache.shiro:shiro-lang 1.13.0 间接依赖 maven
com.esotericsoftware:reflectasm 1.11.9 间接依赖 maven
org.jetbrains.lets-plot:lets-plot-kotlin-jvm 4.5.0 间接依赖 maven
org.apache.xmlgraphics:batik-i18n 1.16 间接依赖 maven
io.burt:jmespath-core 0.6.0 间接依赖 maven
org.springframework.boot:spring-boot-starter-web 3.2.2 直接依赖 maven
com.carrotsearch.thirdparty:simple-xml-safe 2.7.1 间接依赖 maven
com.github.weisj:darklaf-core 2.7.3 间接依赖 maven
com.squareup.okio:okio-jvm 3.6.0 间接依赖 maven
org.eclipse.jetty.websocket:jetty-websocket-jetty-common 12.0.5 间接依赖 maven
io.micrometer:micrometer-observation 1.12.2 间接依赖 maven
org.springframework.ldap:spring-ldap-core 3.2.1 间接依赖 maven
com.github.java-json-tools:json-schema-core 1.2.14 间接依赖 maven
org.springframework.boot:spring-boot-starter-jetty 3.2.2 直接依赖 maven
com.google.errorprone:error_prone_annotations 2.23.0 间接依赖 maven
io.metersphere:metersphere-provider 3.x 直接依赖 maven
commons-io:commons-io 2.15.1 直接依赖 maven
jakarta.activation:jakarta.activation-api 2.1.2 间接依赖 maven
org.apache.commons:commons-math3 3.6.1 间接依赖 maven
org.aspectj:aspectjweaver 1.9.21 间接依赖 maven
com.github.weisj:darklaf-theme 2.7.3 间接依赖 maven
xml-apis:xml-apis 1.4.01 间接依赖 maven
com.google.guava:guava 33.0.0-jre 直接依赖 maven
io.swagger.parser.v3:swagger-parser-v2-converter 2.1.19 间接依赖 maven
io.metersphere:metersphere-api-test 3.x 直接依赖 maven
com.github.jsqlparser:jsqlparser 4.7 间接依赖 maven
org.springframework.boot:spring-boot-starter-validation 3.2.2 直接依赖 maven
org.apache.xmlgraphics:batik-constants 1.16 间接依赖 maven
org.jodd:jodd-props 5.0.13 间接依赖 maven
io.metersphere:metersphere-workstation 3.x 直接依赖 maven
commons-codec:commons-codec 1.16.0 直接依赖 maven
org.springframework:spring-core 6.1.3 间接依赖 maven
bsf:bsf 2.4.0 间接依赖 maven
org.springframework.retry:spring-retry 2.0.5 间接依赖 maven
com.github.zafarkhaja:java-semver 0.9.0 间接依赖 maven
org.apache.shiro:shiro-crypto-core 1.13.0 间接依赖 maven
org.eclipse.jetty.ee10:jetty-ee10-webapp 12.0.5 间接依赖 maven
io.swagger.core.v3:swagger-core-jakarta 2.2.19 间接依赖 maven
org.apache.shiro:shiro-crypto-cipher 1.13.0 间接依赖 maven
org.apache.commons:commons-compress 1.25.0 直接依赖 maven
org.springframework.boot:spring-boot 3.2.2 间接依赖 maven
io.swagger.parser.v3:swagger-parser 2.1.19 直接依赖 maven
org.jetbrains.lets-plot:commons-jvm 4.1.0 间接依赖 maven
com.github.weisj:darklaf-property-loader 2.7.3 间接依赖 maven
org.apache.xmlgraphics:batik-anim 1.16 间接依赖 maven
org.ini4j:ini4j 0.5.4 间接依赖 maven
io.metersphere:metersphere-plugin-platform-sdk 3.x 直接依赖 maven
org.jetbrains.lets-plot:lets-plot-common 4.1.0 间接依赖 maven
org.jetbrains.lets-plot:datamodel-jvm 4.1.0 间接依赖 maven
org.springframework.data:spring-data-ldap 3.2.2 间接依赖 maven
org.apache.shiro:shiro-web 1.13.0 直接依赖 maven
org.apiguardian:apiguardian-api 1.1.2 间接依赖 maven
org.apache.xmlgraphics:xmlgraphics-commons 2.9 间接依赖 maven
com.github.luben:zstd-jni 1.5.5-1 间接依赖 maven
org.eclipse.jetty:jetty-alpn-client 12.0.5 间接依赖 maven
org.eclipse.jetty.ee10:jetty-ee10-servlets 12.0.5 间接依赖 maven
com.fasterxml.jackson.module:jackson-module-parameter-names 2.15.3 间接依赖 maven
org.apache.xmlgraphics:batik-xml 1.16 间接依赖 maven
net.minidev:accessors-smart 2.5.0 间接依赖 maven
org.codehaus.groovy:groovy 3.0.20 间接依赖 maven
org.springframework.data:spring-data-redis 3.2.2 间接依赖 maven
io.projectreactor:reactor-core 3.6.2 间接依赖 maven
com.fasterxml.jackson.core:jackson-databind 2.15.3 直接依赖 maven
org.springframework.boot:spring-boot-starter-aop 3.2.2 直接依赖 maven
com.googlecode.libphonenumber:libphonenumber 8.11.1 间接依赖 maven
io.github.microutils:kotlin-logging 2.0.5 间接依赖 maven
commons-logging:commons-logging 1.2 间接依赖 maven
commons-net:commons-net 3.10.0 间接依赖 maven
org.jetbrains.lets-plot:platf-batik-jvm 4.1.0 间接依赖 maven
javax.cache:cache-api 1.1.1 间接依赖 maven
org.jsoup:jsoup 1.17.1 间接依赖 maven
org.glassfish.jaxb:jaxb-core 4.0.4 间接依赖 maven
xml-apis:xml-apis-ext 1.3.04 间接依赖 maven
org.apache.jmeter:ApacheJMeter_java 5.6.3 直接依赖 maven
org.springframework:spring-jdbc 6.1.3 间接依赖 maven
org.codehaus.groovy:groovy-datetime 3.0.20 间接依赖 maven
org.apache.shiro:shiro-config-ogdl 1.13.0 间接依赖 maven
javax.xml.bind:jaxb-api 2.3.0 间接依赖 maven
org.reactivestreams:reactive-streams 1.0.4 间接依赖 maven
org.apache.shiro:shiro-core 1.13.0 直接依赖 maven
org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-client 12.0.5 间接依赖 maven
com.fasterxml.jackson.core:jackson-annotations 2.15.3 直接依赖 maven
com.aliyun:credentials-java 0.3.0 间接依赖 maven
org.apache.xmlgraphics:batik-bridge 1.16 间接依赖 maven
com.google.code.gson:gson 2.10.1 间接依赖 maven
jcharts:jcharts 0.7.5 间接依赖 maven
io.swagger.core.v3:swagger-annotations-jakarta 2.2.19 间接依赖 maven
org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jakarta-common 12.0.5 间接依赖 maven
org.springframework.boot:spring-boot-starter-json 3.2.2 间接依赖 maven
com.aliyun:tea 1.2.7 间接依赖 maven
org.eclipse.jetty.ee10:jetty-ee10-servlet 12.0.5 间接依赖 maven
io.metersphere:metersphere-sdk 3.x 直接依赖 maven
com.github.weisj:swing-extensions-visual-padding 0.1.3 间接依赖 maven
io.metersphere:metersphere-test-plan 3.x 直接依赖 maven
org.codehaus.groovy:groovy-sql 3.0.20 间接依赖 maven
org.apache.xmlgraphics:batik-shared-resources 1.16 间接依赖 maven
com.squareup.okio:okio 3.6.0 间接依赖 maven
ch.qos.logback:logback-classic 1.4.14 间接依赖 maven
org.apache.commons:commons-text 1.11.0 直接依赖 maven
org.webjars:swagger-ui 5.10.3 间接依赖 maven
org.eclipse.jetty.ee10:jetty-ee10-plus 12.0.5 间接依赖 maven
com.github.bastiaanjansen:otp-java 2.0.1 直接依赖 maven
org.apache.httpcomponents.core5:httpcore5 5.2.4 直接依赖 maven
io.metersphere:dingtalk 2.0.77 直接依赖 maven
com.aliyun:tea-util 0.2.21 间接依赖 maven
io.swagger:swagger-annotations 1.6.12 间接依赖 maven
org.jacoco:org.jacoco.agent 0.8.4 间接依赖 maven
org.apache.poi:poi-ooxml-schemas 4.1.2 间接依赖 maven
io.netty:netty-resolver 4.1.105.Final 间接依赖 maven
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 2.15.3 间接依赖 maven
org.checkerframework:checker-qual 3.37.0 间接依赖 maven
org.jboss.marshalling:jboss-marshalling-river 2.0.11.Final 间接依赖 maven
org.apache.shiro:shiro-crypto-hash 1.13.0 间接依赖 maven
org.apache.logging.log4j:log4j-api 2.21.1 间接依赖 maven
org.apache.poi:poi-ooxml 4.1.2 间接依赖 maven
dnsjava:dnsjava 2.1.9 间接依赖 maven
org.springframework.boot:spring-boot-starter-mail 3.2.2 直接依赖 maven
io.metersphere:metersphere-domain 3.x 直接依赖 maven
org.reflections:reflections 0.10.2 直接依赖 maven
org.glassfish.jaxb:jaxb-runtime 4.0.4 间接依赖 maven
com.esotericsoftware:minlog 1.3.1 间接依赖 maven
org.eclipse.jetty:jetty-server 12.0.5 间接依赖 maven
org.flywaydb:flyway-core 9.22.3 直接依赖 maven
org.redisson:redisson-spring-data-32 3.26.0 间接依赖 maven
org.apache.jmeter:ApacheJMeter 5.6.3 间接依赖 maven
org.apache.httpcomponents:httpclient 4.5.13 间接依赖 maven
com.mysql:mysql-connector-j 8.3.0 直接依赖 maven
io.minio:minio 8.5.7 直接依赖 maven
org.slf4j:jcl-over-slf4j 2.0.11 间接依赖 maven
org.eclipse.jetty:jetty-xml 12.0.5 间接依赖 maven
org.jetbrains.lets-plot:lets-plot-batik 4.1.0 间接依赖 maven
org.apache.logging.log4j:log4j-slf4j-impl 2.21.1 间接依赖 maven
org.json:json 20231013 间接依赖 maven
org.eclipse.jetty:jetty-http 12.0.5 间接依赖 maven
org.apache.xmlbeans:xmlbeans 3.1.0 间接依赖 maven
org.eclipse.jetty.websocket:jetty-websocket-core-common 12.0.5 间接依赖 maven
net.sf.jtidy:jtidy r938 间接依赖 maven
org.mybatis.spring.boot:mybatis-spring-boot-starter 3.0.3 直接依赖 maven
com.github.weisj:darklaf-macos 2.7.3 间接依赖 maven
com.aliyun:gateway-dingtalk 1.0.2 间接依赖 maven
org.apache.shiro:shiro-cache 1.13.0 间接依赖 maven
com.aliyun:tea-openapi 0.3.1 间接依赖 maven
com.sun.xml.bind:jaxb-core 4.0.4 间接依赖 maven
org.springframework.boot:spring-boot-autoconfigure 3.2.2 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-jdk8 1.9.22 间接依赖 maven
org.freemarker:freemarker 2.3.32 间接依赖 maven
org.apache.commons:commons-lang3 3.13.0 直接依赖 maven
org.springframework.session:spring-session-core 3.2.1 间接依赖 maven
com.alibaba:easyexcel-core 3.3.3 间接依赖 maven
com.google.auto.service:auto-service-annotations 1.1.1 间接依赖 maven
com.github.ben-manes.caffeine:caffeine 3.1.8 间接依赖 maven
org.apache.xmlgraphics:batik-gvt 1.16 间接依赖 maven
org.springframework.boot:spring-boot-configuration-processor 3.2.2 直接依赖 maven
org.javassist:javassist 3.28.0-GA 间接依赖 maven
org.springdoc:springdoc-openapi-starter-webmvc-ui 2.3.0 直接依赖 maven
org.flywaydb:flyway-mysql 9.22.3 直接依赖 maven
com.aliyun:openapiutil 0.2.1 间接依赖 maven
com.helger:ph-css 6.5.0 间接依赖 maven
org.apache.poi:poi 4.1.2 间接依赖 maven
org.eclipse.jetty.websocket:jetty-websocket-jetty-api 12.0.5 间接依赖 maven
org.xerial.snappy:snappy-java 1.1.10.5 间接依赖 maven
jakarta.annotation:jakarta.annotation-api 2.1.1 间接依赖 maven
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.15.3 直接依赖 maven
com.github.java-json-tools:jackson-coreutils 2.0 间接依赖 maven
org.apache.xmlgraphics:batik-codec 1.16 间接依赖 maven
org.jetbrains.kotlinx:kotlinx-coroutines-swing 1.7.3 间接依赖 maven
org.ow2.asm:asm 9.6 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib 1.9.22 间接依赖 maven
io.github.x-stream:mxparser 1.2.2 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-common 1.9.22 间接依赖 maven
com.alibaba:easyexcel 3.3.3 直接依赖 maven
org.ehcache:ehcache 3.10.8 间接依赖 maven
com.google.guava:failureaccess 1.0.2 间接依赖 maven
com.google.code.findbugs:jsr305 3.0.2 间接依赖 maven
net.sf.jopt-simple:jopt-simple 5.0.4 间接依赖 maven
org.apache.commons:commons-pool2 2.12.0 间接依赖 maven
org.eclipse.jetty.websocket:jetty-websocket-core-server 12.0.5 间接依赖 maven
oro:oro 2.0.8 间接依赖 maven
io.swagger:swagger-core 1.6.12 间接依赖 maven
org.apache.xmlgraphics:batik-svg-dom 1.16 间接依赖 maven
org.springframework.kafka:spring-kafka 3.1.1 直接依赖 maven
commons-logging:commons-logging 1.0.4 间接依赖 maven
org.redisson:redisson 3.26.0 间接依赖 maven
com.esotericsoftware:kryo 5.6.0 间接依赖 maven
org.jetbrains:annotations 13.0 间接依赖 maven
org.eclipse.jetty:jetty-plus 12.0.5 间接依赖 maven
org.projectlombok:lombok 1.18.30 直接依赖 maven
io.metersphere:metersphere-plugin-sdk 3.x 直接依赖 maven
io.github.microutils:kotlin-logging-jvm 2.0.5 间接依赖 maven
org.springframework:spring-websocket 6.1.3 间接依赖 maven
com.aliyun:tea-xml 0.1.5 间接依赖 maven
com.github.weisj:darklaf-utils 2.7.3 间接依赖 maven
org.jodd:jodd-lagarto 5.0.13 间接依赖 maven
org.springframework:spring-expression 6.1.3 间接依赖 maven
org.eclipse.jetty:jetty-io 12.0.5 间接依赖 maven
org.bouncycastle:bcutil-jdk15on 1.70 间接依赖 maven
org.mozilla:rhino 1.7.14 间接依赖 maven
org.apache-extras.beanshell:bsh 2.0b6 间接依赖 maven
org.springframework.boot:spring-boot-starter-quartz 3.2.2 间接依赖 maven
jakarta.transaction:jakarta.transaction-api 2.0.1 间接依赖 maven
io.metersphere:metersphere-system-setting 3.x 直接依赖 maven
io.netty:netty-codec-dns 4.1.105.Final 间接依赖 maven
com.google.guava:listenablefuture 9999.0-empty-to-avoid-conflict-with-guava 间接依赖 maven
org.apache.shiro:shiro-event 1.13.0 间接依赖 maven
org.springframework:spring-oxm 6.1.3 间接依赖 maven
org.apache.commons:commons-collections4 4.4 直接依赖 maven
org.apache.xmlgraphics:batik-transcoder 1.16 间接依赖 maven
io.metersphere:metersphere-jmeter-assertions 1.0.2 直接依赖 maven
com.fasterxml.jackson.core:jackson-core 2.15.3 间接依赖 maven
org.eclipse.jetty:jetty-util 12.0.5 间接依赖 maven
org.eclipse.jetty.ee10.websocket:jetty-ee10-websocket-jetty-server 12.0.5 间接依赖 maven
org.codehaus.groovy:groovy-jsr223 3.0.20 间接依赖 maven
net.sf.saxon:Saxon-HE 11.6 间接依赖 maven
org.jodd:jodd-bean 5.1.6 间接依赖 maven
net.minidev:json-smart 2.5.0 间接依赖 maven
org.apache.jmeter:ApacheJMeter_components 5.6.3 直接依赖 maven
com.sun.istack:istack-commons-runtime 4.1.2 间接依赖 maven
io.swagger.parser.v3:swagger-parser-safe-url-resolver 2.1.19 间接依赖 maven
org.springframework:spring-aop 6.1.3 间接依赖 maven
org.bouncycastle:bcpkix-jdk15on 1.70 间接依赖 maven
org.apache.shiro:shiro-config-core 1.13.0 间接依赖 maven
org.springframework.data:spring-data-commons 3.2.2 间接依赖 maven
org.apache.logging.log4j:log4j-1.2-api 2.21.1 间接依赖 maven
org.eclipse.jetty:jetty-jndi 12.0.5 间接依赖 maven
io.metersphere:metersphere-project-management 3.x 直接依赖 maven
io.metersphere:metersphere-ui-test 3.x 直接依赖 maven
io.metersphere:metersphere-plugin-api-sdk 3.x 直接依赖 maven
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml 2.15.3 间接依赖 maven
com.github.java-json-tools:msg-simple 1.2 间接依赖 maven
io.metersphere:metersphere-jmeter-functions 3.0 直接依赖 maven
com.github.weisj:darklaf-platform-base 2.7.3 间接依赖 maven
com.fasterxml:classmate 1.6.0 间接依赖 maven
xalan:serializer 2.7.3 间接依赖 maven
org.apache.shiro:shiro-spring-boot-starter 1.13.0 直接依赖 maven
org.springframework:spring-webmvc 6.1.3 间接依赖 maven
org.apache.logging.log4j:log4j-to-slf4j 2.21.1 间接依赖 maven
com.formdev:svgSalamander 1.1.4 间接依赖 maven
org.jodd:jodd-core 5.1.6 间接依赖 maven
org.springframework.boot:spring-boot-starter-data-ldap 3.2.2 直接依赖 maven
org.apache.httpcomponents.core5:httpcore5-h2 5.2.4 间接依赖 maven
org.springframework.boot:spring-boot-starter-logging 3.2.2 间接依赖 maven
org.codehaus.groovy:groovy-json 3.0.20 间接依赖 maven
org.codehaus.groovy:groovy-dateutil 3.0.20 间接依赖 maven
org.apache.logging.log4j:log4j-core 2.21.1 间接依赖 maven
com.helger.commons:ph-commons 10.2.5 间接依赖 maven
org.jetbrains.lets-plot:plot-base-jvm 4.1.0 间接依赖 maven
org.eclipse.jgit:org.eclipse.jgit 6.8.0.202311291450-r 直接依赖 maven
org.apache.shiro:shiro-spring 1.13.0 直接依赖 maven
io.burt:jmespath-jackson 0.6.0 间接依赖 maven
org.mybatis.spring.boot:mybatis-spring-boot-autoconfigure 3.0.3 间接依赖 maven
ch.qos.logback:logback-core 1.4.14 间接依赖 maven
io.metersphere:metersphere-bug-management 3.x 直接依赖 maven
org.eclipse.jetty.websocket:jetty-websocket-core-client 12.0.5 间接依赖 maven
org.apache.tika:tika-core 1.28.5 间接依赖 maven
jakarta.servlet:jakarta.servlet-api 6.0.0 间接依赖 maven
com.thoughtworks.xstream:xstream 1.4.20 间接依赖 maven
org.apache.kafka:kafka-clients 3.6.1 间接依赖 maven
org.bouncycastle:bcprov-jdk18on 1.76 间接依赖 maven
org.ow2.asm:asm-tree 9.6 间接依赖 maven
xmlpull:xmlpull 1.1.3.1 间接依赖 maven
org.springframework.boot:spring-boot-starter 3.2.2 间接依赖 maven
org.eclipse.angus:angus-activation 2.0.1 间接依赖 maven
org.slf4j:slf4j-api 2.0.11 直接依赖 maven
xerces:xercesImpl 2.12.2 间接依赖 maven
org.apache.jmeter:jorphan 5.6.3 直接依赖 maven
org.springframework:spring-jcl 6.1.3 间接依赖 maven
org.springframework.data:spring-data-keyvalue 3.2.2 间接依赖 maven
org.slf4j:jul-to-slf4j 2.0.11 间接依赖 maven
org.apache.httpcomponents:httpmime 4.5.14 间接依赖 maven
io.swagger:swagger-parser 1.0.68 间接依赖 maven
org.springframework:spring-web 6.1.3 直接依赖 maven
org.springframework:spring-beans 6.1.3 间接依赖 maven
org.mybatis:mybatis-spring 3.0.3 间接依赖 maven
io.swagger.parser.v3:swagger-parser-core 2.1.19 间接依赖 maven
org.apache.xmlgraphics:batik-css 1.16 间接依赖 maven
org.apache.xmlgraphics:batik-util 1.16 间接依赖 maven
com.miglayout:miglayout-swing 5.3 间接依赖 maven
jakarta.websocket:jakarta.websocket-api 2.1.1 间接依赖 maven
io.metersphere:metersphere-case-management 3.x 直接依赖 maven
org.yaml:snakeyaml 2.2 间接依赖 maven
org.ow2.asm:asm-commons 9.6 间接依赖 maven
io.swagger.core.v3:swagger-models-jakarta 2.2.19 间接依赖 maven
org.apache.httpcomponents:httpcore 4.4.16 间接依赖 maven
org.eclipse.angus:jakarta.mail 2.0.2 间接依赖 maven
org.jetbrains.kotlin:kotlin-stdlib-jdk7 1.9.22 间接依赖 maven
org.apache.xmlgraphics:batik-ext 1.16 间接依赖 maven
io.swagger:swagger-models 1.6.12 间接依赖 maven
org.jetbrains.lets-plot:deprecated-in-v4-jvm 4.1.0 间接依赖 maven
org.eclipse.jetty.ee10:jetty-ee10-annotations 12.0.5 间接依赖 maven
(0)
上一篇 2024年2月8日
下一篇 2024年2月9日

相关推荐

  • pac4j/spring-security-pac4j 软件分析报告

    基础信息 项目名称:pac4j/spring-security-pac4j 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1751886748134940672/1751886817265459200 此报告由Mu…

    软件分析 2024年1月29日
    0
  • clowwindy/shadowsocks-nodejs 软件分析报告

    基础信息 项目名称:clowwindy/shadowsocks-nodejs 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716744341800222720/1716744342148349952 此报告由M…

    软件分析 2023年10月24日
    0
  • finscn/PoorPhy 软件分析报告

    基础信息 项目名称:finscn/PoorPhy 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721197416807399424/1723284792596193280 此报告由Murphysec提供 漏洞列…

    软件分析 2023年11月11日
    0
  • fatihyildirim1o/aspnet-clean-architecture 软件分析报告

    基础信息 项目名称:fatihyildirim1o/aspnet-clean-architecture 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721188790529163264/172611216284…

    软件分析 2023年11月19日
    0
  • diego2098/ThingsGateway 软件分析报告

    基础信息 项目名称:diego2098/ThingsGateway 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721233338886328320/1726382003049156608 此报告由Murphy…

    软件分析 2023年11月20日
    0