SCA: security update for codechecker (GHSA-fpm5-2wcj-vfr7)

critical Tenable Self-Hosted Container Security Plugin ID 414619

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and
Clang Tidy. Authentication method confusion allows logging in as the built-in root user from an external
service. The built-in root user up until 6.24.1 is generated in a weak manner, cannot be disabled, and has
universal access.This vulnerability allows an attacker who can create an account on an enabled external
authentication service, to log in as the root user, and access and control everything that can be
controlled via the web interface. The attacker needs to acquire the username of the root user to be
successful. This issue affects CodeChecker: through 6.24.1. (CVE-2024-10082)

See Also

https://github.com/advisories/GHSA-fpm5-2wcj-vfr7

Plugin Details

Severity: Critical

ID: 414619

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.66

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2024-10082

CVSS v3

Risk Factor: Critical

Base Score: 9

Temporal Score: 7.8

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.4

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 11/6/2024

Vulnerability Publication Date: 11/6/2024

Reference Information

CVE: CVE-2024-10082

cwe: CWE-305