Lucene search

K
nvd[email protected]NVD:CVE-2023-42658
HistoryOct 31, 2023 - 3:15 p.m.

CVE-2023-42658

2023-10-3115:15:09
CWE-917
CWE-94
web.nvd.nist.gov
2
cve-2023-42658
chef inspec
archive command
maliciously crafted profile
security risk

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

28.3%

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

Affected configurations

Nvd
Node
chefinspecRange<4.56.58
OR
chefinspecRange5.0.05.22.29
VendorProductVersionCPE
chefinspec*cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.7

Confidence

High

EPSS

0.001

Percentile

28.3%

Related for NVD:CVE-2023-42658