[R1] Tenable Appliance 4.7.0 Fixes One Vulnerability

Related Vulnerabilities: CVE-2018-1142  

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.

Synopsis

Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.

Solution

Install the latest Tenable Appliance 4.7.0 by downloading the appropriate installation file available at the Tenable Downloads page (https://www.tenable.com/downloads/tenable-appliance)

Note* - Tenable Appliance 4.7.0 supports the following direct upgrade paths: 4.5, 4.6 → 4.7.0