First published: Tue Oct 11 2022(Updated: )
An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
HashiCorp Vagrant | <2.3.1 | |
Linux Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-42717.
The severity level of CVE-2022-42717 is high (7.8).
The affected software is Hashicorp Vagrant before version 2.3.1.
Non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands.
To fix the vulnerability, upgrade to Hashicorp Vagrant version 2.3.1 or higher.