Alpine: multiple chromium packages: security update to 90.0.4430.72-r0

critical Tenable Self-Hosted Container Security Plugin ID 403820

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to
potentially exploit heap corruption via a crafted Chrome Extension. (CVE-2021-21214)

- Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had
compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
(CVE-2021-21201)

- Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a
user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome
Extension. (CVE-2021-21202)

- Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-21203)

- Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to
potentially exploit heap corruption via a crafted HTML page. (CVE-2021-21204)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-21201

https://security.alpinelinux.org/vuln/CVE-2021-21202

https://security.alpinelinux.org/vuln/CVE-2021-21203

https://security.alpinelinux.org/vuln/CVE-2021-21204

https://security.alpinelinux.org/vuln/CVE-2021-21205

https://security.alpinelinux.org/vuln/CVE-2021-21207

https://security.alpinelinux.org/vuln/CVE-2021-21208

https://security.alpinelinux.org/vuln/CVE-2021-21209

https://security.alpinelinux.org/vuln/CVE-2021-21210

https://security.alpinelinux.org/vuln/CVE-2021-21211

https://security.alpinelinux.org/vuln/CVE-2021-21212

https://security.alpinelinux.org/vuln/CVE-2021-21213

https://security.alpinelinux.org/vuln/CVE-2021-21214

https://security.alpinelinux.org/vuln/CVE-2021-21215

https://security.alpinelinux.org/vuln/CVE-2021-21216

https://security.alpinelinux.org/vuln/CVE-2021-21217

https://security.alpinelinux.org/vuln/CVE-2021-21218

https://security.alpinelinux.org/vuln/CVE-2021-21219

https://security.alpinelinux.org/vuln/CVE-2021-21221

Plugin Details

Severity: Critical

ID: 403820

Version: Revision 1.26

Type: Local

Published: 10/31/2023

Updated: 12/4/2025

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 97.25

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-21214

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS Score Source: CVE-2021-21201

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 4/13/2021

Reference Information

CVE: CVE-2021-21201, CVE-2021-21202, CVE-2021-21203, CVE-2021-21204, CVE-2021-21205, CVE-2021-21207, CVE-2021-21208, CVE-2021-21209, CVE-2021-21210, CVE-2021-21211, CVE-2021-21212, CVE-2021-21213, CVE-2021-21214, CVE-2021-21215, CVE-2021-21216, CVE-2021-21217, CVE-2021-21218, CVE-2021-21219, CVE-2021-21221