SCA: security update for october/system (GHSA-79jw-2f46-wv22)

high Tenable Self-Hosted Container Security Plugin ID 411969

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Octobercms is a self-hosted CMS platform based on the Laravel PHP Framework. In affected versions user
input was not properly sanitized before rendering. An authenticated user with the permissions to create,
modify and delete website pages can exploit this vulnerability to bypass `cms.safe_mode` /
`cms.enableSafeMode` in order to execute arbitrary code. This issue only affects admin panels that rely on
safe mode and restricted permissions. To exploit this vulnerability, an attacker must first have access to
the backend area. The issue has been patched in Build 474 (v1.0.474) and v1.1.10. Users unable to upgrade
should apply https://github.com/octobercms/library/commit/c393c5ce9ca2c5acc3ed6c9bb0dab5ffd61965fe to your
installation manually. (CVE-2022-21705)

See Also

https://github.com/advisories/GHSA-79jw-2f46-wv22

Plugin Details

Severity: High

ID: 411969

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 8.5

Temporal Score: 6.3

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2022-21705

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/23/2022

Vulnerability Publication Date: 2/23/2022

Reference Information

CVE: CVE-2022-21705

cwe: CWE-74