Alpine: qt5-qtwebengine: security update to 5.15.3_git20210510-r4

high Tenable Cloud Security Plugin ID 406837

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Type Confusion in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-30563)

- Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote
attacker to bypass navigation restrictions via a crafted iframe. (CVE-2021-30533)

- Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit stack corruption via a crafted HTML page. (CVE-2021-30536)

- Use after free in V8 in Google Chrome prior to 91.0.4472.164 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-30541)

- Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to
potentially perform out of bounds memory access via a crafted HTML page. (CVE-2021-30547)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-30533

https://security.alpinelinux.org/vuln/CVE-2021-30536

https://security.alpinelinux.org/vuln/CVE-2021-30541

https://security.alpinelinux.org/vuln/CVE-2021-30547

https://security.alpinelinux.org/vuln/CVE-2021-30548

https://security.alpinelinux.org/vuln/CVE-2021-30553

https://security.alpinelinux.org/vuln/CVE-2021-30556

https://security.alpinelinux.org/vuln/CVE-2021-30559

https://security.alpinelinux.org/vuln/CVE-2021-30563

Plugin Details

Severity: High

ID: 406837

Version: Revision 1.31

Type: Local

Published: 10/31/2023

Updated: 2/27/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.6

Percentile: 98.67

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-30563

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/25/2021

CISA Known Exploited Vulnerability Due Dates: 11/17/2021, 7/18/2022

Reference Information

CVE: CVE-2021-30533, CVE-2021-30536, CVE-2021-30541, CVE-2021-30547, CVE-2021-30548, CVE-2021-30553, CVE-2021-30556, CVE-2021-30559, CVE-2021-30563