SCA: security update for github.com/windmill-labs/windmill (GHSA-g6q4-w3j3-jfc4)

medium Tenable Self-Hosted Container Security Plugin ID 446623

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- A vulnerability was found in Windmill 1.380.0. It has been classified as problematic. Affected is an
unknown function of the file backend/windmill-api/src/users.rs of the component HTTP Request Handler. The
manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch
the attack remotely. The complexity of an attack is rather high. The exploitability is told to be
difficult. Upgrading to version 1.390.1 is able to address this issue. The patch is identified as
acfe7786152f036f2476f93ab5536571514fa9e3. It is recommended to upgrade the affected component.
(CVE-2024-8462)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-g6q4-w3j3-jfc4

Plugin Details

Severity: Medium

ID: 446623

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Low

Score: 1.2

Percentile: 0.01

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-8462

CVSS v3

Risk Factor: Low

Base Score: 3.7

Temporal Score: 3.2

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 9/5/2024

Vulnerability Publication Date: 9/5/2024

Reference Information

CVE: CVE-2024-8462

cwe: CWE-307