Alpine: qt5-qtwebengine: security update to 5.15.3_git20210510-r2

high Tenable Self-Hosted Container Security Plugin ID 406835

Description

There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:

- Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially
exploit heap corruption via a crafted HTML page. (CVE-2021-30554)

- Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially
exploit heap corruption via a crafted SCTP packet. (CVE-2021-30523)

- Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker
to perform out of bounds memory access via a crafted HTML page. (CVE-2021-30530)

- Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote
attacker to bypass navigation restrictions via a crafted HTML page. (CVE-2021-30534)

- Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit
heap corruption via a crafted HTML page. (CVE-2021-30535)

See Also

https://security.alpinelinux.org/vuln/CVE-2021-30523

https://security.alpinelinux.org/vuln/CVE-2021-30530

https://security.alpinelinux.org/vuln/CVE-2021-30534

https://security.alpinelinux.org/vuln/CVE-2021-30535

https://security.alpinelinux.org/vuln/CVE-2021-30544

https://security.alpinelinux.org/vuln/CVE-2021-30551

https://security.alpinelinux.org/vuln/CVE-2021-30554

Plugin Details

Severity: High

ID: 406835

Version: Revision 1.37

Type: Local

Published: 10/31/2023

Updated: 3/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.9

Percentile: 99.36

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-30554

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 8.4

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 5/25/2021

CISA Known Exploited Vulnerability Due Dates: 11/17/2021

Reference Information

CVE: CVE-2021-30523, CVE-2021-30530, CVE-2021-30534, CVE-2021-30535, CVE-2021-30544, CVE-2021-30551, CVE-2021-30554