基础信息
项目名称:ACINQ/eclair
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1715509409785626624/1715509409940815872
此报告由Murphysec提供
漏洞列表
漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
---|---|---|---|---|
Quality Open Software logback JNDI注入漏洞 | 反序列化 | MPS-2021-33911 | CVE-2021-42550 | 中危 |
Logback SSL证书校验不当漏洞 | 中间人攻击 | MPS-2022-12411 | 中危 | |
FasterXML jackson-databind 小于2.14.0-rc1拒绝服务漏洞 | 拒绝服务 | MPS-2022-58653 | CVE-2022-42003 | 中危 |
FasterXML jackson-databind 小于2.13.4拒绝服务漏洞 | 拒绝服务 | MPS-2022-58654 | CVE-2022-42004 | 中危 |
Lightbeed Akka Akka-http 临时文件权限不安全漏洞 | 创建拥有不安全权限的临时文件 | MPS-32u5-scjl | CVE-2023-33251 | 中危 |
Lightbeed Akka Akka-http 安全漏洞 | MPS-8hzc-ex6k | CVE-2023-31442 | 高危 | |
Netty 资源管理错误漏洞 | 拒绝服务 | MPS-9u07-bna1 | CVE-2023-34462 | 中危 |
Okio 安全漏洞 | 数值类型间的不正确转换 | MPS-a2tx-d4fb | CVE-2023-3635 | 高危 |
Hot Rod 安全漏洞 | 证书验证不恰当 | MPS-b7oj-adm3 | CVE-2023-4586 | 高危 |
Bouncy Castle 信任管理问题漏洞 | 证书验证不恰当 | MPS-i6w7-d48e | CVE-2023-33201 | 中危 |
【存在争议】FasterXML jackson-databind 代码问题漏洞 | 不加限制或调节的资源分配 | MPS-z1bx-p8y2 | CVE-2023-35116 | 中危 |
缺陷组件
组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
---|---|---|---|---|
io.netty:netty-handler | 4.1.94.Final | 4.1.94.final | 间接依赖 | 建议修复 |
ch.qos.logback:logback-core | 1.2.3 | 1.2.8 | 间接依赖 | 建议修复 |
com.fasterxml.jackson.core:jackson-databind | 2.12.7.1 | 2.14.0-rc1 | 间接依赖 | 建议修复 |
com.fasterxml.jackson.core:jackson-databind | 2.12.7 | 2.14.0-rc1 | 间接依赖 | 建议修复 |
com.squareup.okio:okio-jvm | 3.0.0 | 3.4.0 | 间接依赖 | 建议修复 |
com.typesafe.akka:akka-http_2.13 | 10.2.7 | 10.5.2 | 间接依赖 | 可选修复 |
com.typesafe.akka:akka-actor_2.13 | 2.6.20 | 2.8.1 | 直接依赖 | 可选修复 |
org.bouncycastle:bcprov-jdk15on | 1.70 | 直接依赖 | 可选修复 |
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
自定义许可证 | 10 | 低 |
Apache-2.0 | 129 | 低 |
MPL-2.0 | 1 | 低 |
EPL-1.0 | 2 | 低 |
BSD-3-Clause | 3 | 低 |
LGPL-2.1 | 2 | 中 |
BSD-2-Clause | 2 | 低 |
MIT | 5 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
org.ow2.asm:asm-analysis | 5.0.3 | 间接依赖 | maven |
io.netty:netty-handler | 4.1.94.Final | 间接依赖 | maven |
com.squareup.okhttp3:okhttp | 4.10.0 | 间接依赖 | maven |
fr.acinq.bitcoin:bitcoin-kmp-jvm | 0.13.0 | 间接依赖 | maven |
org.zeromq:jeromq | 0.5.2 | 直接依赖 | maven |
org.ow2.asm:asm-tree | 5.0.3 | 间接依赖 | maven |
org.json4s:json4s-jackson-core_2.13 | 4.0.6 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-common | 0.10.1 | 间接依赖 | maven |
io.kamon:kamon-apm-reporter_2.13 | 2.6.3 | 直接依赖 | maven |
io.netty:netty-codec-dns | 4.1.94.Final | 间接依赖 | maven |
com.google.errorprone:error_prone_annotations | 2.18.0 | 间接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib | 1.8.21 | 间接依赖 | maven |
io.netty:netty-resolver | 4.1.94.Final | 间接依赖 | maven |
commons-codec:commons-codec | 1.15 | 直接依赖 | maven |
ch.qos.logback:logback-classic | 1.2.3 | 直接依赖 | maven |
org.scala-lang.modules:scala-java8-compat_2.13 | 1.0.0 | 间接依赖 | maven |
com.typesafe.akka:akka-http_2.13 | 10.2.7 | 间接依赖 | maven |
org.jetbrains:annotations | 13.0 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-jvm-mingw | 0.10.1 | 间接依赖 | maven |
org.codehaus.janino:janino | 3.1.10 | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-common | 1.8.21 | 间接依赖 | maven |
com.fasterxml.jackson.dataformat:jackson-dataformat-cbor | 2.12.6 | 间接依赖 | maven |
org.xerial:sqlite-jdbc | 3.42.0.0 | 直接依赖 | maven |
com.typesafe.akka:akka-cluster-tools_2.13 | 2.6.20 | 直接依赖 | maven |
com.github.jnr:jnr-constants | 0.9.12 | 间接依赖 | maven |
com.amazonaws:jmespath-java | 1.12.504 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-jvm-linux | 0.10.1 | 间接依赖 | maven |
fr.acinq.eclair:eclair-core_2.13 | 0.9.1-SNAPSHOT | 直接依赖 | maven |
com.github.jsqlparser:jsqlparser | 4.1 | 间接依赖 | maven |
io.netty:netty-transport-rxtx | 4.1.94.Final | 间接依赖 | maven |
org.codehaus.janino:commons-compiler | 3.1.10 | 间接依赖 | maven |
com.typesafe.akka:akka-http-core_2.13 | 10.2.7 | 直接依赖 | maven |
com.typesafe.akka:akka-slf4j_2.13 | 2.6.20 | 直接依赖 | maven |
com.typesafe.akka:akka-coordination_2.13 | 2.6.20 | 间接依赖 | maven |
com.hierynomus:asn-one | 0.5.0 | 间接依赖 | maven |
net.java.dev.jna:jna | 5.8.0 | 间接依赖 | maven |
org.scodec:scodec-bits_2.13 | 1.1.37 | 直接依赖 | maven |
com.typesafe.akka:akka-cluster_2.13 | 2.6.20 | 直接依赖 | maven |
com.chuusai:shapeless_2.13 | 2.3.9 | 间接依赖 | maven |
com.typesafe.akka:akka-actor-typed_2.13 | 2.6.20 | 直接依赖 | maven |
com.typesafe.akka:akka-stream_2.13 | 2.6.20 | 直接依赖 | maven |
org.apache.httpcomponents:httpcore | 4.4.13 | 间接依赖 | maven |
io.kamon:kamon-executors_2.13 | 2.6.3 | 间接依赖 | maven |
io.netty:netty-codec-http2 | 4.1.94.Final | 间接依赖 | maven |
com.amazonaws:aws-java-sdk-secretsmanager | 1.12.504 | 直接依赖 | maven |
io.netty:netty-codec-socks | 4.1.94.Final | 间接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-jdk8 | 1.8.21 | 间接依赖 | maven |
commons-logging:commons-logging | 1.1.3 | 间接依赖 | maven |
io.netty:netty-resolver-dns | 4.1.94.Final | 间接依赖 | maven |
com.typesafe.akka:akka-remote_2.13 | 2.6.20 | 间接依赖 | maven |
org.json4s:json4s-jackson_2.13 | 4.0.6 | 直接依赖 | maven |
io.netty:netty-codec | 4.1.94.Final | 间接依赖 | maven |
com.softwaremill.sttp.client3:core_2.13 | 3.8.16 | 间接依赖 | maven |
org.agrona:agrona | 1.15.1 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-annotations | 2.12.7 | 间接依赖 | maven |
fr.acinq:bitcoin-lib_2.13 | 0.29 | 直接依赖 | maven |
io.netty:netty-codec-mqtt | 4.1.94.Final | 间接依赖 | maven |
org.postgresql:postgresql | 42.6.0 | 直接依赖 | maven |
com.github.oshi:oshi-core | 5.7.5 | 间接依赖 | maven |
com.typesafe.akka:akka-protobuf-v3_2.13 | 2.6.20 | 间接依赖 | maven |
com.typesafe.akka:akka-distributed-data_2.13 | 2.6.20 | 间接依赖 | maven |
org.checkerframework:checker-qual | 3.31.0 | 间接依赖 | maven |
io.kamon:kamon-instrumentation-common_2.13 | 2.6.3 | 间接依赖 | maven |
io.kamon:kamon-akka_2.13 | 2.6.3 | 直接依赖 | maven |
com.fasterxml.jackson.core:jackson-databind | 2.12.7.1 | 间接依赖 | maven |
io.kamon:kanela-agent | 1.0.17 | 直接依赖 | maven |
org.lmdbjava:lmdbjava | 0.7.0 | 间接依赖 | maven |
software.amazon.ion:ion-java | 1.0.2 | 间接依赖 | maven |
io.netty:netty-transport-native-epoll | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-codec-xml | 4.1.94.Final | 间接依赖 | maven |
com.amazonaws:aws-java-sdk-core | 1.12.504 | 间接依赖 | maven |
ch.qos.logback:logback-core | 1.2.3 | 间接依赖 | maven |
com.typesafe:config | 1.4.2 | 间接依赖 | maven |
org.slf4j:slf4j-api | 1.7.25 | 间接依赖 | maven |
com.google.code.findbugs:jsr305 | 3.0.2 | 直接依赖 | maven |
com.github.jnr:jffi | 1.2.18 | 间接依赖 | maven |
org.json4s:json4s-ast_2.13 | 4.0.6 | 间接依赖 | maven |
com.google.guava:listenablefuture | 9999.0-empty-to-avoid-conflict-with-guava | 间接依赖 | maven |
com.github.jnr:jnr-ffi | 2.1.9 | 间接依赖 | maven |
io.netty:netty-resolver-dns-classes-macos | 4.1.94.Final | 间接依赖 | maven |
io.kamon:kamon-system-metrics_2.13 | 2.6.3 | 直接依赖 | maven |
com.google.j2objc:j2objc-annotations | 2.8 | 间接依赖 | maven |
org.apache.httpcomponents:httpclient | 4.5.13 | 间接依赖 | maven |
joda-time:joda-time | 2.8.1 | 间接依赖 | maven |
com.softwaremill.sttp.model:core_2.13 | 1.5.5 | 间接依赖 | maven |
io.netty:netty-transport-native-unix-common | 4.1.94.Final | 间接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib-jdk7 | 1.8.21 | 间接依赖 | maven |
org.json4s:json4s-core_2.13 | 4.0.3 | 间接依赖 | maven |
io.netty:netty-codec-memcache | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-common | 4.1.94.Final | 间接依赖 | maven |
org.scala-lang:scala-library | 2.13.11 | 直接依赖 | maven |
io.netty:netty-transport-classes-kqueue | 4.1.94.Final | 间接依赖 | maven |
com.softwaremill.sttp.client3:json-common_2.13 | 3.8.16 | 间接依赖 | maven |
io.netty:netty-codec-smtp | 4.1.94.Final | 间接依赖 | maven |
com.github.jnr:jnr-a64asm | 1.0.0 | 间接依赖 | maven |
io.kamon:kamon-scala-future_2.13 | 2.6.3 | 间接依赖 | maven |
com.typesafe.akka:akka-actor_2.13 | 2.6.20 | 直接依赖 | maven |
eu.neilalexander:jnacl | 1.0.0 | 间接依赖 | maven |
org.json4s:json4s-ast_2.13 | 4.0.3 | 间接依赖 | maven |
com.typesafe:ssl-config-core_2.13 | 0.4.3 | 间接依赖 | maven |
io.netty:netty-resolver-dns-native-macos | 4.1.94.Final | 间接依赖 | maven |
org.ow2.asm:asm-util | 5.0.3 | 间接依赖 | maven |
com.softwaremill.sttp.client3:json4s_2.13 | 3.8.16 | 直接依赖 | maven |
com.softwaremill.quicklens:quicklens_2.13 | 1.9.4 | 直接依赖 | maven |
org.clapper:grizzled-slf4j_2.13 | 1.3.4 | 直接依赖 | maven |
io.netty:netty-transport-udt | 4.1.94.Final | 间接依赖 | maven |
org.jheaps:jheaps | 0.14 | 直接依赖 | maven |
io.netty:netty-codec-stomp | 4.1.94.Final | 间接依赖 | maven |
org.reactivestreams:reactive-streams | 1.0.3 | 间接依赖 | maven |
org.ow2.asm:asm-commons | 5.0.3 | 间接依赖 | maven |
net.java.dev.jna:jna-platform | 5.8.0 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-databind | 2.12.7 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jvm | 0.10.1 | 间接依赖 | maven |
com.typesafe.akka:akka-cluster-typed_2.13 | 2.6.20 | 直接依赖 | maven |
org.json4s:json4s-scalap_2.13 | 4.0.3 | 间接依赖 | maven |
io.netty:netty-transport-classes-epoll | 4.1.94.Final | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-core | 2.12.7 | 间接依赖 | maven |
com.typesafe.akka:akka-pki_2.13 | 2.6.20 | 间接依赖 | maven |
com.typesafe.akka:akka-parsing_2.13 | 10.2.7 | 间接依赖 | maven |
org.json4s:json4s-scalap_2.13 | 4.0.6 | 间接依赖 | maven |
io.kamon:kamon-prometheus_2.13 | 2.6.3 | 直接依赖 | maven |
com.google.guava:guava | 32.1.1-jre | 直接依赖 | maven |
com.github.jnr:jnr-x86asm | 1.0.2 | 间接依赖 | maven |
io.netty:netty-transport-native-kqueue | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-transport | 4.1.94.Final | 间接依赖 | maven |
io.kamon:kamon-core_2.13 | 2.6.3 | 直接依赖 | maven |
com.thoughtworks.paranamer:paranamer | 2.8 | 间接依赖 | maven |
com.softwaremill.sttp.shared:core_2.13 | 1.3.13 | 间接依赖 | maven |
io.netty:netty-all | 4.1.94.Final | 直接依赖 | maven |
org.scala-lang.modules:scala-collection-contrib_2.13 | 0.2.1 | 直接依赖 | maven |
io.netty:netty-codec-http | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-transport-sctp | 4.1.94.Final | 间接依赖 | maven |
com.softwaremill.sttp.client3:okhttp-backend_2.13 | 3.8.16 | 直接依赖 | maven |
org.jetbrains.kotlin:kotlin-stdlib | 1.6.20 | 间接依赖 | maven |
io.netty:netty-handler-ssl-ocsp | 4.1.94.Final | 间接依赖 | maven |
org.slf4j:slf4j-api | 1.7.36 | 间接依赖 | maven |
io.kamon:kamon-jdbc_2.13 | 2.6.3 | 直接依赖 | maven |
org.scodec:scodec-core_2.13 | 1.11.10 | 直接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-jvm-extract | 0.10.1 | 间接依赖 | maven |
org.ow2.asm:asm | 5.0.3 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-jvm-darwin | 0.10.1 | 间接依赖 | maven |
org.json4s:json4s-core_2.13 | 4.0.6 | 间接依赖 | maven |
fr.acinq.secp256k1:secp256k1-kmp-jni-jvm | 0.10.1 | 间接依赖 | maven |
com.google.guava:failureaccess | 1.0.1 | 间接依赖 | maven |
io.netty:netty-buffer | 4.1.94.Final | 间接依赖 | maven |
com.squareup.okio:okio-jvm | 3.0.0 | 间接依赖 | maven |
de.heikoseeberger:akka-http-json4s_2.13 | 1.39.2 | 直接依赖 | maven |
org.bouncycastle:bcprov-jdk15on | 1.70 | 直接依赖 | maven |
org.scala-lang.modules:scala-parser-combinators_2.13 | 1.1.2 | 间接依赖 | maven |
com.softwaremill.sttp.shared:ws_2.13 | 1.3.13 | 间接依赖 | maven |
com.zaxxer:HikariCP | 4.0.3 | 直接依赖 | maven |
io.netty:netty-codec-redis | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-handler-proxy | 4.1.94.Final | 间接依赖 | maven |
io.netty:netty-codec-haproxy | 4.1.94.Final | 间接依赖 | maven |