Alpine: multiple nheko packages: security update to 0.9.3-r2

medium Tenable Self-Hosted Container Security Plugin ID 405773

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are
vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users
can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch
manually, avoid doing verifications of one's own devices, and/or avoid pressing the request button in the
settings menu. (CVE-2022-39264)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-39264

Plugin Details

Severity: Medium

ID: 405773

Version: Revision 1.31

Type: Local

Published: 10/31/2023

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

CVSS v2

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:C/A:N

CVSS Score Source: CVE-2022-39264

CVSS v3

Risk Factor: Medium

Base Score: 5.9

Temporal Score: 5.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 9/28/2022

Reference Information

CVE: CVE-2022-39264