[R1] Tenable.sc 5.21.0 Fixes Multiple Third-Party Vulnerabilities

Related Vulnerabilities: CVE-2022-0778   CVE-2022-23943   CVE-2022-24828   CVE-2021-41116   CVE-2021-41182   CVE-2021-41183   CVE-2021-41184   CVE-2022-24785   CVE-2021-21707  

Tenable.sc leverages third-party software to help provide underlying functionality. Several of the third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers. Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc 5.21.0 updates the following components to address the identified vulnerabilities: jQuery UI upgraded from 1.12.0 to 1.13.1 MomentJS upgraded from 2.29.1 to 2.29.2 PHP upgraded from 8.0.12 to 8.0.16 Apache upgraded from 2.4.52 to 2.4.53 OpenSSL upgraded from 1.1.1(L) to 1.1.1(n)

Synopsis

Tenable.sc leverages third-party software to help provide underlying functionality. Several of the third-party components were found to contain vulnerabilities, and updated versions have been made available by the providers.

Out of caution, and in line with best practice, Tenable has upgraded the bundled components to address the potential impact of these issues. Tenable.sc 5.21.0 updates the following components to address the identified vulnerabilities:

jQuery UI upgraded from 1.12.0 to 1.13.1
MomentJS upgraded from 2.29.1 to 2.29.2
PHP upgraded from 8.0.12 to 8.0.16
Apache upgraded from 2.4.52 to 2.4.53
OpenSSL upgraded from 1.1.1(L) to 1.1.1(n)

Solution

Tenable has released Tenable.sc 5.21.0 to address these issues. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/tenable-sc).