SCA: security update for microsoft/microsoft-graph-core (GHSA-mhhp-c3cm-2r86)

medium Tenable Self-Hosted Container Security Plugin ID 416980

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- microsoft-graph-core the Microsoft Graph Library for PHP. The Microsoft Graph Beta PHP SDK published
packages which contained test code that enabled the use of the phpInfo() function from any application
that could access and execute the file at `vendor/microsoft/microsoft-graph-core/tests/GetPhpInfo.php`.
The phpInfo function exposes system information. The vulnerability affects the GetPhpInfo.php script of
the PHP SDK which contains a call to the phpinfo() function. This vulnerability requires a
misconfiguration of the server to be present so it can be exploited. For example, making the PHP
application’s /vendor directory web accessible. The combination of the vulnerability and the server
misconfiguration would allow an attacker to craft an HTTP request that executes the phpinfo() method. The
attacker would then be able to get access to system information like configuration, modules, and
environment variables and later on use the compromised secrets to access additional data. This problem has
been patched in version 2.0.2. If an immediate deployment with the updated vendor package is not
available, you can perform the following temporary workarounds: delete the `vendor/microsoft/microsoft-
graph-core/tests/GetPhpInfo.php` file, remove access to the /vendor directory, or disable the phpinfo
function (CVE-2023-49283)

See Also

https://github.com/advisories/GHSA-mhhp-c3cm-2r86

Plugin Details

Severity: Medium

ID: 416980

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.2

Percentile: 51.06

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2023-49283

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/5/2023

Vulnerability Publication Date: 12/5/2023

Reference Information

CVE: CVE-2023-49283

cwe: CWE-200