SCA: security update for october/system (GHSA-8v7h-cpc2-r8jp)

high Tenable Cloud Security Plugin ID 412858

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- October/System is the system module for October CMS, a self-hosted CMS platform based on the Laravel PHP
Framework. Prior to versions 1.0.476, 1.1.12, and 2.2.15, when the developer allows the user to specify
their own filename in the `fromData` method, an unauthenticated user can perform remote code execution
(RCE) by exploiting a race condition in the temporary storage directory. This vulnerability affects
plugins that expose the `October\Rain\Database\Attach\File::fromData` as a public interface and does not
affect vanilla installations of October CMS since this method is not exposed or used by the system
internally or externally. The issue has been patched in Build 476 (v1.0.476), v1.1.12, and v2.2.15. Those
who are unable to upgrade may apply with patch to their installation manually as a workaround.
(CVE-2022-24800)

See Also

https://github.com/advisories/GHSA-8v7h-cpc2-r8jp

Plugin Details

Severity: High

ID: 412858

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-24800

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/13/2022

Vulnerability Publication Date: 7/12/2022

Reference Information

CVE: CVE-2022-24800

cwe: CWE-362