Alpine: multiple tailscale packages: security update to 1.32.3-r0

critical Tenable Self-Hosted Container Security Plugin ID 426114

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability identified in the Tailscale Windows client allows a malicious website to reconfigure the
Tailscale daemon `tailscaled`, which can then be used to remotely execute code. In the Tailscale Windows
client, the local API was bound to a local TCP socket, and communicated with the Windows client GUI in
cleartext with no Host header verification. This allowed an attacker-controlled website visited by the
node to rebind DNS to an attacker-controlled DNS server, and then make local API requests in the client,
including changing the coordination server to an attacker-controlled coordination server. An attacker-
controlled coordination server can send malicious URL responses to the client, including pushing
executables or installing an SMB share. These allow the attacker to remotely execute code on the node. All
Windows clients prior to version v.1.32.3 are affected. If you are running Tailscale on Windows, upgrade
to v1.32.3 or later to remediate the issue. (CVE-2022-41924)

See Also

https://security.alpinelinux.org/vuln/CVE-2022-41924

Plugin Details

Severity: Critical

ID: 426114

Version: Revision 1.5

Type: Local

Published: 5/16/2025

Updated: 7/2/2026

Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.06

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-41924

CVSS v3

Risk Factor: Critical

Base Score: 9.6

Temporal Score: 8.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Vulnerability Publication Date: 11/21/2022

Reference Information

CVE: CVE-2022-41924