基础信息
项目名称:beremiz/beremiz
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1716302376675704832/1716302382686142464
此报告由Murphysec提供
漏洞列表
| 漏洞名称 | 漏洞类型 | MPS编号 | CVE编号 | 漏洞等级 |
|---|---|---|---|---|
| NumPy 代码问题漏洞 | 空指针取消引用 | MPS-2021-32278 | CVE-2021-41495 | 中危 |
| OpenSSL 安全漏洞 | 过度迭代 | MPS-n3pe-ljgc | CVE-2023-3817 | 中危 |
| python-cryptography 信任管理问题漏洞 | 证书验证不恰当 | MPS-sj5m-20tf | CVE-2023-38325 | 高危 |
缺陷组件
| 组件名称 | 版本 | 最小修复版本 | 依赖关系 | 修复建议 |
|---|---|---|---|---|
| cryptography | 40.0.2 | 41.0.3 | 间接依赖 | 建议修复 |
| numpy | 1.24.3 | 间接依赖 | 可选修复 |
许可证风险
| 许可证类型 | 相关组件 | 许可证风险 |
|---|---|---|
| 自定义许可证 | 10 | 低 |
| LGPL-2.1 | 1 | 中 |
| BSD-3-Clause | 4 | 低 |
| MIT | 17 | 低 |
| GPL-2.0-or-later | 1 | 低 |
| Apache-2.0 | 5 | 低 |
| PSF-2.0 AND (Apache-2.0 OR BSD-3-Clause) | 1 | 低 |
| HPND | 1 | 低 |
SBOM清单
| 组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
|---|---|---|---|
| wxPython | 4.2.1 | 间接依赖 | pip |
| pycountry | 22.3.5 | 间接依赖 | pip |
| lxml | 4.9.2 | 间接依赖 | pip |
| ConnectorSchemes | 间接依赖 | pip | |
| autobahn | 23.1.2 | 间接依赖 | pip |
| Brotli | 1.0.9 | 间接依赖 | pip |
| six | 1.16.0 | 间接依赖 | pip |
| kiwisolver | 1.4.4 | 间接依赖 | pip |
| hyperlink | 21.0.0 | 间接依赖 | pip |
| matplotlib | 3.7.1 | 间接依赖 | pip |
| EditorClassFromScheme | 间接依赖 | pip | |
| bacnet-stack | 间接依赖 | ||
| bacnet-stack | 1.0.0 | 间接依赖 | |
| Twisted | 22.10.0 | 间接依赖 | pip |
| txaio | 23.1.1 | 间接依赖 | pip |
| ifaddr | 0.2.0 | 间接依赖 | pip |
| pyparsing | 3.0.9 | 间接依赖 | pip |
| aiofiles | 23.1.0 | 间接依赖 | pip |
| cffi | 1.15.1 | 间接依赖 | pip |
| incremental | 22.10.0 | 间接依赖 | pip |
| msgpack | 1.0.5 | 间接依赖 | pip |
| Pyro5 | 5.14 | 间接依赖 | pip |
| gattrdict | 2.0.1 | 间接依赖 | pip |
| python-dateutil | 2.8.2 | 间接依赖 | pip |
| cryptography | 40.0.2 | 间接依赖 | pip |
| etherlab | 间接依赖 | pip | |
| idna | 3.4 | 间接依赖 | pip |
| contourpy | 1.0.7 | 间接依赖 | pip |
| zope.interface | 6.0 | 间接依赖 | pip |
| click | 8.1.3 | 间接依赖 | pip |
| serpent | 1.41 | 间接依赖 | pip |
| pycparser | 2.21 | 间接依赖 | pip |
| zeroconf | 0.62.0 | 间接依赖 | pip |
| /home/$UNAME/requirements.txt | 间接依赖 | pip | |
| packaging | 23.1 | 间接依赖 | pip |
| Automat | 22.10.0 | 间接依赖 | pip |
| async-timeout | 4.0.2 | 间接依赖 | pip |
| aiosqlite | 0.19.0 | 间接依赖 | pip |
| numpy | 1.24.3 | 间接依赖 | pip |
| typing_extensions | 4.5.0 | 间接依赖 | pip |
| attrs | 23.1.0 | 间接依赖 | pip |
| Pillow | 9.5.0 | 间接依赖 | pip |
| constantly | 15.1.0 | 间接依赖 | pip |
| sortedcontainers | 2.4.0 | 间接依赖 | pip |
| fonttools | 4.39.3 | 间接依赖 | pip |
| pytz | 2023.3 | 间接依赖 | pip |
| cycler | 0.11.0 | 间接依赖 | pip |