SCA: security update for github.com/grafana/synthetic-monitoring-agent, github.com/grafana/synthetic-monitoring-agent/cmd/synthetic-monitoring-agent (GHSA-9j4f-f249-q5w8)

medium Tenable Cloud Security Plugin ID 434037

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The Synthetic Monitoring Agent for Grafana's Synthetic Monitoring application provides probe functionality
and executes network checks for monitoring remote targets. Users running the Synthetic Monitoring agent
prior to version 0.12.0 in their local network are impacted. The authentication token used to communicate
with the Synthetic Monitoring API is exposed through a debugging endpoint. This token can be used to
retrieve the Synthetic Monitoring checks created by the user and assigned to the agent identified with
that token. The Synthetic Monitoring API will reject connections from already-connected agents, so access
to the token does not guarantee access to the checks. Version 0.12.0 contains a fix. Users are advised to
rotate the agent tokens. After upgrading to version v0.12.0 or later, it's recommended that users of
distribution packages review the configuration stored in `/etc/synthetic-monitoring/synthetic-monitoring-
agent.conf`, specifically the `API_TOKEN` variable which has been renamed to `SM_AGENT_API_TOKEN`. As a
workaround for previous versions, it's recommended that users review the agent settings and set the HTTP
listening address in a manner that limits the exposure, for example, localhost or a non-routed network, by
using the command line parameter `-listen-address`, e.g. `-listen-address localhost:4050`.
(CVE-2022-46156)

See Also

https://github.com/advisories/GHSA-9j4f-f249-q5w8

Plugin Details

Severity: Medium

ID: 434037

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 8/19/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 51.06

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 1.7

Temporal Score: 1.3

Vector: CVSS2#AV:L/AC:L/Au:S/C:P/I:N/A:N

CVSS Score Source: CVE-2022-46156

CVSS v3

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.9

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Threat Score: 2.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/6/2024

Vulnerability Publication Date: 11/30/2022

Reference Information

CVE: CVE-2022-46156