SCA: security update for @octokit/app, @octokit/webhooks, octokit, probot (GHSA-pwfr-8pq7-x9qv)

high Tenable Cloud Security Plugin ID 417739

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3,
10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the
@octokit/webhooks library because the error can be undefined in some cases. The resulting request was
found to cause an uncaught exception that ends the nodejs process. The bug is fixed in octokit/webhooks.js
9.26.3, 10.9.2, 11.1.2, and 12.0.4, app.js 14.02, octokit.js 3.1.2, and Protobot 12.3.3. (CVE-2023-50728)

See Also

https://github.com/advisories/GHSA-pwfr-8pq7-x9qv

Plugin Details

Severity: High

ID: 417739

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS Score Source: CVE-2023-50728

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/16/2023

Vulnerability Publication Date: 12/15/2023

Reference Information

CVE: CVE-2023-50728

cwe: CWE-755