SCA: security update for pyinstaller (GHSA-9w2p-rh8c-v9g5)

high Tenable Cloud Security Plugin ID 413490

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller
built application, elevated as a privileged process, may be tricked by an unprivileged attacker into
deleting files the unprivileged user does not otherwise have access to. A user is affected if **all** the
following are satisfied: 1. The user runs an application containing either `matplotlib` or `win32com`. 2.
The application is ran as administrator (or at least a user with higher privileges than the attacker). 3.
The user's temporary directory is not locked to that specific user (most likely due to `TMP`/`TEMP`
environment variables pointing to an unprotected, arbitrary, non default location). Either: A. The
attacker is able to very carefully time the replacement of a temporary file with a symlink. This switch
must occur exactly between `shutil.rmtree()`'s builtin symlink check and the deletion itself B: The
application was built with Python 3.7.x or earlier which has no protection against Directory Junctions
links. The vulnerability has been addressed in PR #7827 which corresponds to `pyinstaller >= 5.13.1`.
Users are advised to upgrade. There are no known workarounds for this vulnerability. (CVE-2023-49797)

See Also

https://github.com/advisories/GHSA-9w2p-rh8c-v9g5

Plugin Details

Severity: High

ID: 413490

Version: Revision 1.18

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-49797

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/9/2023

Vulnerability Publication Date: 12/9/2023

Reference Information

CVE: CVE-2023-49797