SCA: security update for formidable (GHSA-8cp3-66vr-3r4c)

critical Tenable Cloud Security Plugin ID 432882

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An arbitrary file upload vulnerability in formidable v3.1.4 allows attackers to execute arbitrary code via
a crafted filename. NOTE: some third parties dispute this issue because the product has common use cases
in which uploading arbitrary files is the desired behavior. Also, there are configuration options in all
versions that can change the default behavior of how files are handled. Strapi does not consider this to
be a valid vulnerability. (CVE-2022-29622)

See Also

https://github.com/advisories/GHSA-8cp3-66vr-3r4c

Plugin Details

Severity: Critical

ID: 432882

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 8/11/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2022-29622

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/17/2022

Vulnerability Publication Date: 5/16/2022

Reference Information

CVE: CVE-2022-29622

cwe: CWE-434