Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT Security Bulletin ASB-2019.0168 A vulnerability has been identified in Tenable Nessus 26 June 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: Tenable Nessus Operating System: Windows UNIX variants (UNIX, Linux, OSX) Impact/Access: Cross-site Scripting -- Remote with User Interaction Resolution: Patch/Upgrade Member content until: Friday, July 26 2019 OVERVIEW A vulnerability has been identified in Tenable Nessus. [1] IMPACT Tenable has provided the following details regarding the vulnerability: "Nessus versions 8.4.0 and earlier were found to contain a reflected XSS vulnerability due to improper validation of user-supplied input. An unauthenticated, remote attacker could potentially exploit this vulnerability via a specially crafted request to execute arbitrary script code in a user's browser session." [1] MITIGATION Tenable recommends users upgrade to the latest version to address this issue. [1] "Tenable has released Nessus 8.5.0 to address this issue. The installation files can be obtained from the Tenable Downloads Portal (https://www.tenable.com/downloads/nessus)" [1] REFERENCES [1] [R1] Nessus 8.5.0 Fixes One Vulnerability https://www.tenable.com/security/tns-2019-04 AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXRLDj2aOgq3Tt24GAQjzMg/+O/Ke/eOAjiuqU56zhd2EBG4lkv3Mu6Mo Lx4w+DG6XIniwxIdsHLUC3kuvdmwPC8HytZOXiqYLE8Aqg479A7+VGmqZG3jW5KE cNEO/EkdcrE/7VoC8Ug62oDo6wdZouA/bvtpu97rJpGaLz+qtWpJ5PtQR0JU/pPB 6FZepuLein8cyo1NJ0ya6HQIOeUBdULfbNULbGy4RToXOqxjrnxGAGHGVma+x1EF fxBXSKAuAqnDotz+2qr3SSK1y1rYoerNXXcitEoylop9s1xiIGorYsCJYHiFo4mW 8eqlvJQaIB9PzF1+dKnNjAhAfi46tSchLi/1x1rjt74vBmBvi6zIDvu5wK1DbtAS qAkcDL3TBghjfEa+yQMDtWmGZSn9/dtMPwHLxAdhe5flFm8GJ1c+JVLTh2RNlba4 Jgd3JA71I9Vqjp3vkvgvTpQKzwMKSVvUzAMC0QTKCnp9qHOSxn72aRJ/4DgUPLD+ AKJ+Eb88Rc+7oMdEEtvVjWjJRVHdyIvagc0DRymP0eOffCBwSL53IcrJtFO+R29j eW1pLd/OU8A3GEzE88A0igduX8CbdYe8rKIUG+pkif6UwEqYf+8qyYi/ff72z6Gt Nvg4xb6UcZpi2UK9++6psijHSP59oC1ZkAdz8YvjKyr7cgIRIJn3ucYwCnR2XUeU Y/4xVmFQfHI= =q0w8 -----END PGP SIGNATURE-----