SCA: security update for github.com/lf-edge/eve (GHSA-3mq9-xhgq-r7gj)

high Tenable Self-Hosted Container Security Plugin ID 437552

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- On boot, the Pillar eve container checks for the existence and content of “/config/authorized_keys”. If
the file is present, and contains a supported public key, the container will go on to open port 22 and
enable sshd with the given keys as the authorized keys for root login. An attacker could easily add their
own keys and gain full control over the system without triggering the “measured boot” mechanism
implemented by EVE OS, and without marking the device as “UUD” (“Unknown Update Detected”). This is
because the “/config” partition is not protected by “measured boot”, it is mutable, and it is not
encrypted in any way. An attacker can gain full control over the device without changing the PCR values,
thus not triggering the “measured boot” mechanism, and having full access to the vault. Note: This issue
was partially fixed in these commits (after disclosure to Zededa), where the config partition measurement
was added to PCR13: • aa3501d6c57206ced222c33aea15a9169d629141 • 5fef4d92e75838cc78010edaed5247dfbdae1889.
This issue was made viable in version 9.0.0 when the calculation was moved to PCR14 but it was not
included in the measured boot. (CVE-2023-43631)

See Also

https://github.com/advisories/GHSA-3mq9-xhgq-r7gj

Plugin Details

Severity: High

ID: 437552

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 2/5/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7

Percentile: 98.33

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2023-43631

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/4/2026

Vulnerability Publication Date: 9/21/2023

Reference Information

CVE: CVE-2023-43631