SCA: security update for sulu/sulu (GHSA-84px-q68r-2fc9)

high Tenable Self-Hosted Container Security Plugin ID 412427

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions
Sulu users who have access to any subset of the admin UI are able to elevate their privilege. Over the API
it was possible for them to give themselves permissions to areas which they did not already had. This
issue was introduced in 2.0.0-RC1 with the new ProfileController putAction. The versions have been patched
in 2.2.18, 2.3.8 and 2.4.0. For users unable to upgrade the only known workaround is to apply a patch to
the ProfileController manually. (CVE-2021-43835)

See Also

https://github.com/advisories/GHSA-84px-q68r-2fc9

Plugin Details

Severity: High

ID: 412427

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.12

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 4.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS Score Source: CVE-2021-43835

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/15/2021

Vulnerability Publication Date: 12/15/2021

Reference Information

CVE: CVE-2021-43835

cwe: CWE-269