SCA: security update for pyramid (GHSA-j8g2-6fc7-q8f8)

medium Tenable Cloud Security Plugin ID 416244

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0
and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path
and have a `index.html` file that is located exactly one directory above the location of the static view's
file system path. No further path traversal exists, and the only file that could be disclosed accidentally
is `index.html`. Pyramid version 2.0.2 rejects any path that contains a null-byte out of caution. While
valid in directory/file names, we would strongly consider it a mistake to use null-bytes in naming
files/directories. Secondly, Python 3.11, and 3.12 has fixed the underlying issue in `os.path.normpath` to
no longer truncate on the first `0x00` found, returning the behavior to pre-3.11 Python, un an as of yet
unreleased version. Fixes will be available in:Python 3.12.0rc2 and 3.11.5. Some workarounds are
available. Use a version of Python 3 that is not affected, downgrade to Python 3.10 series temporarily, or
wait until Python 3.11.5 is released and upgrade to the latest version of Python 3.11 series.
(CVE-2023-40587)

See Also

https://github.com/advisories/GHSA-j8g2-6fc7-q8f8

Plugin Details

Severity: Medium

ID: 416244

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-40587

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/25/2023

Vulnerability Publication Date: 8/25/2023

Reference Information

CVE: CVE-2023-40587

cwe: CWE-22