SCA: security update for github.com/csaf-poc/csaf_distribution (GHSA-xxfx-w2rw-gh63)

medium Tenable Self-Hosted Container Security Plugin ID 420745

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- The csaf_provider package before 0.8.2 allows XSS via a crafted CSAF document uploaded as text/html. The
endpoint upload allows valid CSAF advisories (JSON format) to be uploaded with Content-Type text/html and
filenames ending in .html. When subsequently accessed via web browser, these advisories are served and
interpreted as HTML pages. Such uploaded advisories can contain JavaScript code that will execute within
the browser context of users inspecting the advisory. (CVE-2022-43996)

See Also

https://github.com/advisories/GHSA-xxfx-w2rw-gh63

Plugin Details

Severity: Medium

ID: 420745

Version: Revision 1.7

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 6/1/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.0

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2022-43996

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/14/2022

Vulnerability Publication Date: 12/13/2022

Reference Information

CVE: CVE-2022-43996

cwe: CWE-79