SCA: security update for tailscale.com (GHSA-vfgq-g5x8-g595)

high Tenable Cloud Security Plugin ID 419295

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Tailscale is software for using Wireguard and multi-factor authentication (MFA). A vulnerability
identified in the implementation of Tailscale SSH starting in version 1.34.0 and prior to prior to 1.38.2
in FreeBSD allows commands to be run with a higher privilege group ID than that specified in Tailscale SSH
access rules. A difference in the behavior of the FreeBSD `setgroups` system call from POSIX meant that
the Tailscale client running on a FreeBSD-based operating system did not appropriately restrict groups on
the host when using Tailscale SSH. When accessing a FreeBSD host over Tailscale SSH, the egid of the
tailscaled process was used instead of that of the user specified in Tailscale SSH access rules. Tailscale
SSH commands may have been run with a higher privilege group ID than that specified in Tailscale SSH
access rules if they met all of the following criteria: the destination node was a FreeBSD device with
Tailscale SSH enabled; Tailscale SSH access rules permitted access for non-root users; and a non-
interactive SSH session was used. Affected users should upgrade to version 1.38.2 to remediate the issue.
(CVE-2023-28436)

See Also

https://github.com/advisories/GHSA-vfgq-g5x8-g595

Plugin Details

Severity: High

ID: 419295

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.12

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.7

Temporal Score: 5.7

Vector: CVSS2#AV:A/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-28436

CVSS v3

Risk Factor: High

Base Score: 8

Temporal Score: 7

Vector: CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/23/2023

Vulnerability Publication Date: 3/23/2023

Reference Information

CVE: CVE-2023-28436

cwe: CWE-269