CVE-2023-40050: Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application
Published Oct 31, 2023
·Updated
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
Affected Software
1 affected component
Chef Automate<=4.10.29
Remediation
Information
Solution (optional): Customers should adopt the latest releases of Automate available from the customer downloads portal.
Event History
Oct 31, 2023
CVE Published
02:07 PM
Data Sourced
02:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-40050.
2
What is the severity of CVE-2023-40050?
The severity of CVE-2023-40050 is critical with a CVSS score of 9.9.
3
What is the affected software for CVE-2023-40050?
The affected software for CVE-2023-40050 is Chef Automate versions prior to and including 4.10.29.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by uploading a profile with a maliciously crafted content through the API or user interface in Chef Automate.
5
How can I fix CVE-2023-40050?
To fix CVE-2023-40050, update to a version of Chef Automate that is newer than 4.10.29.