SCA: security update for roar-pidusage (GHSA-xfxf-qw26-hr33)

high Tenable Self-Hosted Container Security Plugin ID 446832

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- This affects all versions of package roar-pidusage. If attacker-controlled user input is given to the stat
function of this package on certain operating systems, it is possible for an attacker to execute arbitrary
commands. This is due to use of the child_process exec function without input sanitization.
(CVE-2021-23380)

Solution

There is no known solution at this time.

See Also

https://github.com/advisories/GHSA-xfxf-qw26-hr33

Plugin Details

Severity: High

ID: 446832

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/31/2026

Updated: 8/31/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.8

Percentile: 22.22

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.9

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2021-23380

CVSS v3

Risk Factor: High

Base Score: 7.3

Temporal Score: 6.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 5/6/2021

Vulnerability Publication Date: 4/18/2021

Reference Information

CVE: CVE-2021-23380

cwe: CWE-77