Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Solution (optional): Customers should adopt the latest releases of InSpec on the 4, 5, and 6 supported versions available from the community and customer downloads portals.
Vendor Workaround
Workaround (optional): Chef recommends all users to manually inspect and lint with a tool similar to test-kitchen all profiles and cookbooks prior to usage in production.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-47091 | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile. |
No history.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2024-09-06T16:00:52.926Z
Reserved: 2023-09-12T13:30:29.571Z
Link: CVE-2023-42658
Updated: 2024-08-02T19:23:40.222Z
Status : Modified
Published: 2023-10-31T15:15:09.393
Modified: 2024-11-21T08:22:54.187
Link: CVE-2023-42658
No data.
OpenCVE Enrichment
No data.
EUVD