SCA: security update for github.com/lf-edge/eve (GHSA-phcg-h58r-gmcq)

high Tenable Self-Hosted Container Security Plugin ID 437544

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- PCR14 is not in the list of PCRs that seal/unseal the “vault” key, but due to the change that was
implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, fixing this issue alone would not solve
the problem of the config partition not being measured correctly. Also, the “vault” key is sealed/unsealed
with SHA1 PCRs instead of SHA256. This issue was somewhat mitigated due to all of the PCR extend functions
updating both the values of SHA256 and SHA1 for a given PCR ID. However, due to the change that was
implemented in commit “7638364bc0acf8b5c481b5ce5fea11ad44ad7fd4”, this is no longer the case for PCR14, as
the code in “measurefs.go” explicitly updates only the SHA256 instance of PCR14, which means that even if
PCR14 were to be added to the list of PCRs sealing/unsealing the “vault” key, changes to the config
partition would still not be measured. An attacker could modify the config partition without triggering
the measured boot, this could result in the attacker gaining full control over the device with full access
to the contents of the encrypted “vault” (CVE-2023-43630)

See Also

https://github.com/advisories/GHSA-phcg-h58r-gmcq

Plugin Details

Severity: High

ID: 437544

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 2/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.33

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-43630

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/4/2026

Vulnerability Publication Date: 9/20/2023

Reference Information

CVE: CVE-2023-43630