SCA: security update for dbt-core (GHSA-pmrx-695r-4349)

medium Tenable Self-Hosted Container Security Plugin ID 417609

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- dbt enables data analysts and engineers to transform their data using the same practices that software
engineers use to build applications. Prior to versions 1.6.15, 1.7.15, and 1.8.1, Binding to `INADDR_ANY
(0.0.0.0)` or `IN6ADDR_ANY (::)` exposes an application on all network interfaces, increasing the risk of
unauthorized access. As stated in the Python docs, a special form for address is accepted instead of a
host address: `''` represents `INADDR_ANY`, equivalent to `"0.0.0.0"`. On systems with IPv6, '' represents
`IN6ADDR_ANY`, which is equivalent to `"::"`. A user who serves docs on an unsecured public network, may
unknowingly be hosting an unsecured (http) web site for any remote user/system to access on the same
network. The issue has has been mitigated in dbt-core v1.6.15, dbt-core v1.7.15, and dbt-core v1.8.1 by
binding to localhost explicitly by default in `dbt docs serve`. (CVE-2024-36105)

See Also

https://github.com/advisories/GHSA-pmrx-695r-4349

Plugin Details

Severity: Medium

ID: 417609

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-36105

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2024

Vulnerability Publication Date: 5/27/2024

Reference Information

CVE: CVE-2024-36105