Lucene search

K
prionPRIOn knowledge basePRION:CVE-2022-42717
HistoryOct 11, 2022 - 11:15 p.m.

Design/Logic Flaw

2022-10-1123:15:00
PRIOn knowledge base
www.prio-n.com
1
hashicorp packer
sudoers configuration
insecure
non-privileged users
arbitrary commands
linux

0.0004 Low

EPSS

Percentile

12.8%

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

CPENameOperatorVersion
vagrantlt2.3.1

0.0004 Low

EPSS

Percentile

12.8%