CVE-2023-42658

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*
cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-10-31 15:15

Updated : 2023-11-08 17:38


NVD link : CVE-2023-42658

Mitre link : CVE-2023-42658

CVE.ORG link : CVE-2023-42658


JSON object : View

Products Affected

chef

  • inspec
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-917

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')