SCA: security update for better_errors (GHSA-w3j4-76qw-wwjm)

high Tenable Self-Hosted Container Security Plugin ID 419659

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- better_errors is an open source replacement for the standard Rails error page with more information rich
error pages. It is also usable outside of Rails in any Rack app as Rack middleware. better_errors prior to
2.8.0 did not implement CSRF protection for its internal requests. It also did not enforce the correct
"Content-Type" header for these requests, which allowed a cross-origin "simple request" to be made without
CORS protection. These together left an application with better_errors enabled open to cross-origin
attacks. As a developer tool, better_errors documentation strongly recommends addition only to the
`development` bundle group, so this vulnerability should only affect development environments. Please
ensure that your project limits better_errors to the `development` group (or the non-Rails equivalent).
Starting with release 2.8.x, CSRF protection is enforced. It is recommended that you upgrade to the latest
release, or minimally to "~> 2.8.3". There are no known workarounds to mitigate the risk of using older
releases of better_errors. (CVE-2021-39197)

See Also

https://github.com/advisories/GHSA-w3j4-76qw-wwjm

Plugin Details

Severity: High

ID: 419659

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.15

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-39197

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/7/2021

Vulnerability Publication Date: 9/7/2021

Reference Information

CVE: CVE-2021-39197

cwe: CWE-352