SCA: security update for app-builder-lib (GHSA-r4pf-3v7r-hh55)

high Tenable Self-Hosted Container Security Plugin ID 418484

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app
for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in
Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script.
NSExec by default searches the current directory of where the installer is located before searching
`PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same
folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No
known workaround exists. The code executes at the installer-level before the app is present on the system,
so there's no way to check if it exists in a current installer. (CVE-2024-27303)

Solution

Update the app-builder-lib library and its related packages to version 24.13.2 or later.

See Also

https://github.com/advisories/GHSA-r4pf-3v7r-hh55

Plugin Details

Severity: High

ID: 418484

Version: Revision 1.17

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.75

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-27303

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.4

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/4/2024

Vulnerability Publication Date: 3/4/2024

Reference Information

CVE: CVE-2024-27303