SCA: security update for io.swagger:swagger-codegen (GHSA-pc22-3g76-gm6j)

high Tenable Cloud Security Plugin ID 417443

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- swagger-codegen is an open-source project which contains a template-driven engine to generate
documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger
definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary
directory is shared between all users on that system. A collocated user can observe the process of
creating a temporary sub directory in the shared temporary directory and race to complete the creation of
the temporary subdirectory. This vulnerability is local privilege escalation because the contents of the
`outputFolder` can be appended to by an attacker. As such, code written to this directory, when executed
can be attacker controlled. For more details refer to the referenced GitHub Security Advisory. This
vulnerability is fixed in version 2.4.19. Note this is a distinct vulnerability from CVE-2021-21364.
(CVE-2021-21363)

See Also

https://github.com/advisories/GHSA-pc22-3g76-gm6j

Plugin Details

Severity: High

ID: 417443

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: Low

CVSS v2

Risk Factor: Medium

Base Score: 4.4

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-21363

CVSS v3

Risk Factor: High

Base Score: 7

Temporal Score: 6.3

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/11/2021

Vulnerability Publication Date: 3/11/2021

Reference Information

CVE: CVE-2021-21363