SCA: security update for psitransfer (GHSA-2p2x-p7wj-j5h2)

medium Tenable Cloud Security Plugin ID 409000

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PsiTransfer is an open source, self-hosted file sharing solution. Prior to version 2.2.0, the absence of
restrictions on the endpoint, which is designed for uploading files, allows an attacker who received the
id of a file distribution to change the files that are in this distribution. The vulnerability allows an
attacker to influence those users who come to the file distribution after them and slip the victim files
with a malicious or phishing signature. Version 2.2.0 contains a patch for this issue. CVE-2024-31454
allows users to violate the integrity of a file that is uploaded by another user. In this case, additional
files are not loaded into the file bucket. Violation of integrity at the level of individual files. While
the vulnerability with the number CVE-2024-31453 allows users to violate the integrity of a file bucket
without violating the integrity of files uploaded by other users. Thus, vulnerabilities are reproduced
differently, require different security recommendations and affect different objects of the application’s
business logic. (CVE-2024-31454)

See Also

https://github.com/advisories/GHSA-2p2x-p7wj-j5h2

Plugin Details

Severity: Medium

ID: 409000

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/20/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.92

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2024-31454

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 4/5/2024

Vulnerability Publication Date: 4/5/2024

Reference Information

CVE: CVE-2024-31454

cwe: CWE-434