SCA: security update for @snyk/snyk-cocoapods-plugin, @snyk/snyk-hex-plugin, snyk, snyk-docker-plugin, snyk-gradle-plugin, snyk-mvn-plugin, snyk-python-plugin, snyk-sbt-plugin (GHSA-4x6g-3cmx-w76r)

medium Tenable Self-Hosted Container Security Plugin ID 410472

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The package snyk before 1.1064.0; the package snyk-mvn-plugin before 2.31.3; the package snyk-gradle-
plugin before 3.24.5; the package @snyk/snyk-cocoapods-plugin before 2.5.3; the package snyk-sbt-plugin
before 2.16.2; the package snyk-python-plugin before 1.24.2; the package snyk-docker-plugin before 5.6.5;
the package @snyk/snyk-hex-plugin before 1.1.6 are vulnerable to Command Injection due to an incomplete
fix for [CVE-2022-40764](https://security.snyk.io/vuln/SNYK-JS-SNYK-3037342). A successful exploit allows
attackers to run arbitrary commands on the host system where the Snyk CLI is installed by passing in
crafted command line flags. In order to exploit this vulnerability, a user would have to execute the snyk
test command on untrusted files. In most cases, an attacker positioned to control the command line
arguments to the Snyk CLI would already be positioned to execute arbitrary commands. However, this could
be abused in specific scenarios, such as continuous integration pipelines, where developers can control
the arguments passed to the Snyk CLI to leverage this component as part of a wider attack against an
integration/build pipeline. This issue has been addressed in the latest Snyk Docker images available at
https://hub.docker.com/r/snyk/snyk as of 2022-11-29. Images downloaded and built prior to that date should
be updated. The issue has also been addressed in the Snyk TeamCity CI/CD plugin as of version
v20221130.093605. (CVE-2022-22984)

See Also

https://github.com/advisories/GHSA-4x6g-3cmx-w76r

Plugin Details

Severity: Medium

ID: 410472

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.22

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2022-22984

CVSS v3

Risk Factor: Medium

Base Score: 6.3

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/30/2022

Vulnerability Publication Date: 11/30/2022

Reference Information

CVE: CVE-2022-22984

cwe: CWE-78