SCA: security update for org.apache.helix:helix-core, org.apache.helix:helix-rest (GHSA-jhcr-hph9-g7wm)

critical Tenable Self-Hosted Container Security Plugin ID 416386

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a
specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader.
This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST
start and Workflow creation. Affect all the versions lower and include 1.2.0. Affected products: helix-
core, helix-rest Mitigation: Short term, stop using any YAML based configuration and workflow creation.
Long term, all Helix version bumping up to 1.3.0 (CVE-2023-38647)

See Also

https://github.com/advisories/GHSA-jhcr-hph9-g7wm

Plugin Details

Severity: Critical

ID: 416386

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-38647

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.3

Threat Score: 8.1

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 7/26/2023

Vulnerability Publication Date: 7/26/2023

Reference Information

CVE: CVE-2023-38647

cwe: CWE-502