SCA: security update for microsoft/microsoft-graph (GHSA-cgwq-6prq-8h9q)

medium Tenable Self-Hosted Container Security Plugin ID 413900

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- msgraph-sdk-php is the Microsoft Graph Library for PHP. The Microsoft Graph PHP SDK published packages
which contained test code that enabled the use of the phpInfo() function from any application that could
access and execute the file at vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php. The phpInfo function
exposes system information. The vulnerability affects the GetPhpInfo.php script of the PHP SDK which
contains a call to the phpinfo() function. This vulnerability requires a misconfiguration of the server to
be present so it can be exploited. For example, making the PHP application’s /vendor directory web
accessible. The combination of the vulnerability and the server misconfiguration would allow an attacker
to craft an HTTP request that executes the phpinfo() method. The attacker would then be able to get access
to system information like configuration, modules, and environment variables and later on use the
compromised secrets to access additional data. This problem has been patched in versions 1.109.1 and
2.0.0-RC5. If an immediate deployment with the updated vendor package is not available, you can perform
the following temporary workarounds: delete the `vendor/microsoft/microsoft-graph/tests/GetPhpInfo.php`
file, remove access to the `/vendor` directory, or disable the phpinfo function. (CVE-2023-49282)

See Also

https://github.com/advisories/GHSA-cgwq-6prq-8h9q

Plugin Details

Severity: Medium

ID: 413900

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-49282

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/5/2023

Vulnerability Publication Date: 12/5/2023

Reference Information

CVE: CVE-2023-49282

cwe: CWE-200