SCA: security update for github.com/lf-edge/eve (GHSA-g7vp-j25f-h34p)

high Tenable Self-Hosted Container Security Plugin ID 437546

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Due to the implementation of "deriveVaultKey", prior to version 7.10, the generated vault key would always
have the last 16 bytes predetermined to be "arfoobarfoobarfo". This issue happens because "deriveVaultKey"
calls "retrieveCloudKey" (which will always return "foobarfoobarfoobarfoobarfoobarfo" as the key), and
then merges the 32byte randomly generated key with this key (by takeing 16bytes from each, see
"mergeKeys"). This makes the key a lot weaker. This issue does not persist in devices that were
initialized on/after version 7.10, but devices that were initialized before that and updated to a newer
version still have this issue. Roll an update that enforces the full 32bytes key usage. (CVE-2023-43637)

See Also

https://github.com/advisories/GHSA-g7vp-j25f-h34p

Plugin Details

Severity: High

ID: 437546

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 2/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.88

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-43637

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/4/2026

Vulnerability Publication Date: 9/21/2023

Reference Information

CVE: CVE-2023-43637