SCA: security update for cachethq/cachet (GHSA-hv79-p62r-wg3p)

high Tenable Self-Hosted Container Security Plugin ID 415950

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Cachet, the open-source status page system. Prior to the 2.4 branch, a template functionality which allows
users to create templates allows them to execute any code on the server during the bad filtration and old
twig version. Commit 6fb043e109d2a262ce3974e863c54e9e5f5e0587 of the 2.4 branch contains a patch for this
issue. (CVE-2023-43661)

See Also

https://github.com/advisories/GHSA-hv79-p62r-wg3p

Plugin Details

Severity: High

ID: 415950

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-43661

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 10/16/2023

Vulnerability Publication Date: 10/11/2023

Reference Information

CVE: CVE-2023-43661