arquillian/arquillian-graphene 软件分析报告

基础信息

项目名称:arquillian/arquillian-graphene

项目徽章:

Security Status

仓库地址:https://github.com/pterodactyl/panel

检测报告地址:https://www.murphysec.com/console/report/1716042534047498240/1716042534823444480

此报告由Murphysec提供

漏洞列表

漏洞名称 漏洞类型 MPS编号 CVE编号 漏洞等级
Eclipse Jetty 资源管理错误漏洞 拒绝服务 MPS-0e59-bdsi CVE-2023-36478 高危
Apache Commons Compress 存在拒绝服务漏洞 不可达退出条件的循环(无限循环) MPS-2018-11233 CVE-2018-11771 中危
Apache Commons Compress 安存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10550 CVE-2021-35517 高危
Apache Commons Compress 存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10551 CVE-2021-35516 高危
Apache Commons Compress 存在拒绝服务漏洞 不加限制或调节的资源分配 MPS-2021-10564 CVE-2021-36090 高危
Apache Commons Compress 无限循环漏洞 不可达退出条件的循环(无限循环) MPS-2021-10565 CVE-2021-35515 高危
jsoup 不可达退出条件的循环(无限循环) MPS-2021-17634 CVE-2021-37714 高危
Apache Commons Net 未授权敏感信息泄露 MPS-2021-28440 CVE-2021-37533 中危
commons-codec:commons-codec 存在信息泄露漏洞 未授权敏感信息泄露 MPS-2022-11853 低危
io.netty:netty-handler 存在证书验证不恰当漏洞 证书验证不恰当 MPS-2022-12067 中危
Eclipse Jetty URI注入漏洞 注入 MPS-2022-18060 CVE-2022-2047 低危
Apache Xalan 存在整数截断漏洞 数值截断错误 MPS-2022-19461 CVE-2022-34169 中危
Netty 存在信息泄露漏洞 将资源暴露给错误范围 MPS-2022-3790 CVE-2022-24823 中危
jsoup XSS MPS-2022-51547 CVE-2022-36033 中危
Netty 解释冲突 MPS-2022-58552 CVE-2022-41915 中危
Apache Commons Text 反序列化 MPS-2022-59712 CVE-2022-42889 严重
HtmlUnit 堆缓冲区溢出 MPS-2022-9087 CVE-2022-29546 高危
Eclipse Jetty 安全漏洞 MPS-49ot-3w07 CVE-2023-40167 中危
HtmlUnit 缓冲区错误漏洞 越界写入 MPS-7106-nyuw CVE-2023-2798 高危
Netty 资源管理错误漏洞 拒绝服务 MPS-9u07-bna1 CVE-2023-34462 中危
Hot Rod 安全漏洞 证书验证不恰当 MPS-b7oj-adm3 CVE-2023-4586 高危
Guava 创建拥有不安全权限的临时文件 MPS-mfku-xzh3 CVE-2023-2976 中危

缺陷组件

组件名称 版本 最小修复版本 依赖关系 修复建议
net.sourceforge.htmlunit:htmlunit 2.58.0 2.70.0 间接依赖 建议修复
xalan:xalan 2.7.2 间接依赖 建议修复
io.netty:netty-handler 4.1.73.Final 4.1.94.final 间接依赖 建议修复
org.apache.commons:commons-text 1.9 1.10.0 间接依赖 建议修复
org.apache.commons:commons-compress 1.8.1 1.24.0 间接依赖 建议修复
org.eclipse.jetty:jetty-http 9.4.44.v20210927 12.0.1 间接依赖 可选修复
io.netty:netty-codec-http 4.1.73.Final 4.1.86.final 间接依赖 可选修复
org.jsoup:jsoup 1.12.1 1.15.3 间接依赖 可选修复
commons-codec:commons-codec 1.11 1.13 间接依赖 可选修复
commons-net:commons-net 3.8.0 3.9.0 间接依赖 可选修复
io.netty:netty-common 4.1.73.Final 4.1.77.Final 间接依赖 可选修复
net.sourceforge.htmlunit:neko-htmlunit 2.58.0 2.61.0 间接依赖 可选修复
com.google.guava:guava 31.0.1-jre 32.0.0-jre 间接依赖 可选修复

许可证风险

许可证类型 相关组件 许可证风险
Apache-2.0 106
自定义许可证 22
LGPL-2.1 4
BSD-2-Clause 1
EPL-1.0 4
MIT 4
MPL-2.0 1
BSD-3-Clause 1

SBOM清单

组件名称 组件版本 是否直接依赖 仓库
org.seleniumhq.selenium:selenium-edge-driver 4.1.2 间接依赖 maven
com.jhlabs:filters 2.0.235 间接依赖 maven
org.jboss.arquillian.config:arquillian-config-spi 1.6.0.Final 间接依赖 maven
org.arquillian.extension:arquillian-recorder-spi 1.1.6.Final 间接依赖 maven
io.opentelemetry:opentelemetry-api 1.10.1 间接依赖 maven
io.netty:netty-transport-native-kqueue 4.1.73.Final 间接依赖 maven
io.netty:netty-transport-native-epoll 4.1.60.Final 间接依赖 maven
com.google.guava:guava 31.0.1-jre 间接依赖 maven
io.netty:netty-handler-proxy 4.1.60.Final 间接依赖 maven
org.arquillian.extension:arquillian-recorder-screenshooter-impl-base 1.1.6.Final 直接依赖 maven
xalan:serializer 2.7.2 间接依赖 maven
io.netty:netty-tcnative-classes 2.0.46.Final 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-webdriver-depchain 3.0.0-alpha.5 直接依赖 maven
org.jboss.arquillian.graphene:graphene-webdriver-spi 3.0.0-SNAPSHOT 直接依赖 maven
net.sourceforge.htmlunit:htmlunit-cssparser 1.11.0 间接依赖 maven
io.netty:netty-buffer 4.1.73.Final 间接依赖 maven
commons-io:commons-io 2.11.0 间接依赖 maven
com.google.guava:failureaccess 1.0.1 间接依赖 maven
com.shapesecurity:salvation2 3.0.0 间接依赖 maven
org.seleniumhq.selenium:selenium-devtools-v97 4.1.2 间接依赖 maven
org.eclipse.jetty:jetty-io 9.4.44.v20210927 间接依赖 maven
io.netty:netty-transport-native-unix-common 4.1.73.Final 间接依赖 maven
org.seleniumhq.selenium:htmlunit-driver 3.58.0 间接依赖 maven
org.hamcrest:hamcrest 2.1 间接依赖 maven
org.asynchttpclient:async-http-client-netty-utils 2.12.3 间接依赖 maven
net.sourceforge.htmlunit:neko-htmlunit 2.58.0 间接依赖 maven
org.seleniumhq.selenium:selenium-java 4.1.2 直接依赖 maven
org.seleniumhq.selenium:selenium-devtools-v95 4.1.2 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-webdriver 3.0.0-alpha.5 直接依赖 maven
org.arquillian.spacelift:arquillian-spacelift 1.0.2 间接依赖 maven
org.jboss.arquillian.container:arquillian-container-test-spi 1.6.0.Final 直接依赖 maven
net.bytebuddy:byte-buddy 1.12.7 间接依赖 maven
org.awaitility:awaitility 4.2.0 间接依赖 maven
org.eclipse.jetty.websocket:websocket-client 9.4.44.v20210927 间接依赖 maven
org.arquillian.extension:arquillian-recorder-screenshooter-spi 1.1.6.Final 直接依赖 maven
org.seleniumhq.selenium:selenium-chrome-driver 4.1.2 间接依赖 maven
org.apache.commons:commons-lang3 3.8.1 间接依赖 maven
net.sourceforge.htmlunit:htmlunit 2.58.0 间接依赖 maven
io.opentelemetry:opentelemetry-exporter-logging 1.10.1 间接依赖 maven
org.apache.httpcomponents:httpclient 4.5.13 间接依赖 maven
com.codeborne:phantomjsdriver 1.5.0 间接依赖 maven
io.netty:netty-common 4.1.73.Final 间接依赖 maven
commons-net:commons-net 3.8.0 间接依赖 maven
org.eclipse.persistence:org.eclipse.persistence.moxy 2.5.1 间接依赖 maven
org.eclipse.jetty.websocket:websocket-api 9.4.44.v20210927 间接依赖 maven
org.asynchttpclient:async-http-client 2.12.3 间接依赖 maven
org.apache.httpcomponents:httpmime 4.5.13 间接依赖 maven
org.jboss.arquillian.test:arquillian-test-api 1.6.0.Final 间接依赖 maven
org.apache.commons:commons-text 1.9 间接依赖 maven
io.opentelemetry:opentelemetry-sdk 1.10.1 间接依赖 maven
org.arquillian.extension:arquillian-recorder-api 1.1.6.Final 间接依赖 maven
commons-logging:commons-logging 1.2 间接依赖 maven
io.netty:netty-transport-classes-epoll 4.1.73.Final 间接依赖 maven
org.seleniumhq.selenium:selenium-ie-driver 4.1.2 间接依赖 maven
org.seleniumhq.selenium:selenium-opera-driver 4.1.2 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-spi 3.0.0-alpha.5 间接依赖 maven
org.objenesis:objenesis 3.3 直接依赖 maven
org.jboss.arquillian.graphene:graphene-webdriver-impl 3.0.0-SNAPSHOT 直接依赖 maven
org.jboss.arquillian.test:arquillian-test-spi 1.6.0.Final 直接依赖 maven
io.netty:netty-resolver 4.1.73.Final 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-api 3.0.0-alpha.5 间接依赖 maven
io.opentelemetry:opentelemetry-semconv 1.10.1-alpha 间接依赖 maven
org.arquillian.extension:arquillian-recorder-reporter-api 1.1.6.Final 间接依赖 maven
org.eclipse.persistence:org.eclipse.persistence.core 2.5.1 间接依赖 maven
io.netty:netty-handler 4.1.73.Final 间接依赖 maven
org.apache.httpcomponents:httpcore 4.4.13 间接依赖 maven
com.google.auto.service:auto-service 1.0.1 间接依赖 maven
xalan:xalan 2.7.2 间接依赖 maven
org.slf4j:slf4j-api 1.7.29 间接依赖 maven
com.google.guava:listenablefuture 9999.0-empty-to-avoid-conflict-with-guava 间接依赖 maven
org.checkerframework:checker-qual 3.12.0 间接依赖 maven
com.typesafe.netty:netty-reactive-streams 2.0.4 间接依赖 maven
org.seleniumhq.selenium:selenium-api 4.1.2 间接依赖 maven
net.sourceforge.htmlunit:htmlunit-core-js 2.58.0 间接依赖 maven
org.seleniumhq.selenium:selenium-firefox-driver 4.1.2 间接依赖 maven
org.eclipse.persistence:org.eclipse.persistence.asm 2.5.1 间接依赖 maven
io.netty:netty-transport-classes-kqueue 4.1.73.Final 间接依赖 maven
org.seleniumhq.selenium:selenium-safari-driver 4.1.2 间接依赖 maven
io.opentelemetry:opentelemetry-sdk-logs 1.10.1-alpha 间接依赖 maven
io.netty:netty-codec-http 4.1.73.Final 间接依赖 maven
com.sun.activation:jakarta.activation 1.2.2 间接依赖 maven
com.google.code.gson:gson 2.9.0 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-impl 3.0.0-alpha.5 直接依赖 maven
org.jboss.arquillian.container:arquillian-container-test-api 1.6.0.Final 间接依赖 maven
io.netty:netty-transport-native-epoll 4.1.73.Final 间接依赖 maven
com.beust:jcommander 1.82 间接依赖 maven
org.arquillian.extension:arquillian-recorder-screenshooter-api 1.1.6.Final 间接依赖 maven
org.seleniumhq.selenium:selenium-devtools-v85 4.1.2 间接依赖 maven
io.opentelemetry:opentelemetry-sdk-metrics 1.10.1-alpha 间接依赖 maven
org.reactivestreams:reactive-streams 1.0.3 间接依赖 maven
org.arquillian.extension:arquillian-recorder-reporter-impl 1.1.6.Final 间接依赖 maven
org.apache.commons:commons-compress 1.8.1 间接依赖 maven
org.apache.commons:commons-exec 1.3 间接依赖 maven
io.netty:netty-codec 4.1.73.Final 间接依赖 maven
commons-codec:commons-codec 1.11 间接依赖 maven
com.google.code.findbugs:jsr305 3.0.2 间接依赖 maven
net.jodah:failsafe 2.4.4 间接依赖 maven
org.jboss.arquillian.extension:arquillian-drone-configuration 3.0.0-alpha.5 直接依赖 maven
org.seleniumhq.selenium:selenium-devtools-v96 4.1.2 间接依赖 maven
org.eclipse.jetty:jetty-http 9.4.44.v20210927 间接依赖 maven
org.jboss.arquillian.core:arquillian-core-spi 1.6.0.Final 直接依赖 maven
org.seleniumhq.selenium:selenium-json 4.1.2 间接依赖 maven
org.seleniumhq.selenium:selenium-chromium-driver 4.1.2 间接依赖 maven
xerces:xercesImpl 2.12.2 间接依赖 maven
org.jboss.arquillian.graphene:graphene-webdriver-api 3.0.0-SNAPSHOT 直接依赖 maven
org.eclipse.jetty:jetty-client 9.4.44.v20210927 间接依赖 maven
org.jboss.arquillian.container:arquillian-container-spi 1.6.0.Final 直接依赖 maven
org.arquillian.extension:arquillian-recorder-video-api 1.1.6.Final 间接依赖 maven
org.jsoup:jsoup 1.12.1 间接依赖 maven
org.jboss.arquillian.config:arquillian-config-api 1.6.0.Final 直接依赖 maven
org.seleniumhq.selenium:selenium-support 4.1.2 间接依赖 maven
org.jboss.arquillian.core:arquillian-core-api 1.6.0.Final 间接依赖 maven
com.google.j2objc:j2objc-annotations 1.3 间接依赖 maven
org.seleniumhq.selenium:selenium-remote-driver 4.1.2 间接依赖 maven
org.eclipse.jetty.websocket:websocket-common 9.4.44.v20210927 间接依赖 maven
io.netty:netty-transport-native-kqueue 4.1.60.Final 间接依赖 maven
org.jboss.arquillian.config:arquillian-config-impl-base 1.6.0.Final 间接依赖 maven
org.hamcrest:hamcrest-all 1.3 直接依赖 maven
io.netty:netty-transport 4.1.73.Final 间接依赖 maven
io.opentelemetry:opentelemetry-sdk-common 1.10.1 间接依赖 maven
org.arquillian.extension:arquillian-recorder-reporter-spi 1.1.6.Final 间接依赖 maven
io.ous:jtoml 2.0.0 间接依赖 maven
cglib:cglib 3.3.0 直接依赖 maven
org.ow2.asm:asm 9.4 间接依赖 maven
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-spi 2.0.0 间接依赖 maven
io.netty:netty-codec-socks 4.1.60.Final 间接依赖 maven
com.google.auto:auto-common 1.2 间接依赖 maven
com.google.auto.service:auto-service-annotations 1.0.1 间接依赖 maven
io.opentelemetry:opentelemetry-sdk-extension-autoconfigure 1.10.1-alpha 间接依赖 maven
com.google.errorprone:error_prone_annotations 2.7.1 间接依赖 maven
org.eclipse.jetty:jetty-util 9.4.44.v20210927 间接依赖 maven
org.jboss.shrinkwrap.descriptors:shrinkwrap-descriptors-api-base 2.0.0 间接依赖 maven
io.opentelemetry:opentelemetry-context 1.10.1 间接依赖 maven
xml-apis:xml-apis 1.4.01 间接依赖 maven
org.seleniumhq.selenium:selenium-http 4.1.2 间接依赖 maven
org.jboss.arquillian.graphene:graphene-webdriver 3.0.0-SNAPSHOT 直接依赖 maven
io.opentelemetry:opentelemetry-sdk-extension-autoconfigure-spi 1.10.1 间接依赖 maven
org.brotli:dec 0.1.2 间接依赖 maven
org.seleniumhq.selenium:selenium-firefox-xpi-driver 4.1.2 间接依赖 maven
org.eclipse.persistence:org.eclipse.persistence.antlr 2.5.1 间接依赖 maven
org.arquillian.spacelift:arquillian-spacelift-api 1.0.2 间接依赖 maven
org.jboss.shrinkwrap:shrinkwrap-api 1.2.6 间接依赖 maven
io.opentelemetry:opentelemetry-sdk-trace 1.10.1 间接依赖 maven
(0)
上一篇 2023年10月23日
下一篇 2023年10月23日

相关推荐

  • floodsung/Deep-Learning-Papers-Reading-Roadmap 软件分析报告

    基础信息 项目名称:floodsung/Deep-Learning-Papers-Reading-Roadmap 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721201579473833984/1730939…

    软件分析 2023年12月2日
    0
  • LibrePhotos/librephotos 软件分析报告

    基础信息 项目名称:LibrePhotos/librephotos 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1746054064368164864/1755414375080136704 此报告由Murphy…

    软件分析 2024年2月8日
    0
  • ibm/type 软件分析报告

    基础信息 项目名称:ibm/type 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1718755851867127808/1718755851946819584 此报告由Murphysec提供 漏洞列表 暂无 缺…

    软件分析 2023年10月30日
    0
  • dlemel8/tunneler 软件分析报告

    基础信息 项目名称:dlemel8/tunneler 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1721137244047216640/1725772621964337152 此报告由Murphysec提供 漏…

    软件分析 2023年11月18日
    0
  • chinese-poetry/chinese-poetry 软件分析报告

    基础信息 项目名称:chinese-poetry/chinese-poetry 项目徽章: 仓库地址:https://github.com/pterodactyl/panel 检测报告地址:https://www.murphysec.com/console/report/1716649849649938432/1716649849687687168 此报告由…

    软件分析 2023年10月24日
    0