Lucene search

K
cvelistProgressSoftwareCVELIST:CVE-2023-42658
HistoryOct 31, 2023 - 2:08 p.m.

CVE-2023-42658 InSpec Archive Command Vulnerable to Maliciously Crafted Profile

2023-10-3114:08:03
CWE-94
CWE-917
ProgressSoftware
www.cve.org
2
chef inspec
local execution
malicious profile
cve-2023-42658

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

28.3%

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

CNA Affected

[
  {
    "collectionURL": "https://community.chef.io/downloads/tools/inspec?os=windows",
    "defaultStatus": "affected",
    "modules": [
      "InSpec Archive",
      "InSpec Check",
      "InSpec Export"
    ],
    "packageName": "InSpec",
    "platforms": [
      "Windows",
      "Linux",
      "MacOS"
    ],
    "product": "Chef InSpec",
    "repo": "https://github.com/inspec/inspec",
    "vendor": "Progress Software Corporation",
    "versions": [
      {
        "lessThan": "4.56.58 ",
        "status": "affected",
        "version": "4.0.0",
        "versionType": "semver"
      },
      {
        "lessThan": "5.22.29",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

8.8

Confidence

High

EPSS

0.001

Percentile

28.3%

Related for CVELIST:CVE-2023-42658