CVE-2023-40050: Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application

Published Oct 31, 2023
·
Updated

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

Affected Software

1 affected component
Chef Automate<=4.10.29

Remediation

Information

Solution (optional): Customers should adopt the latest releases of Automate available from the customer downloads portal.

Event History

Oct 31, 2023
CVE Published
02:07 PM
Data Sourced
02:07 PM
RemedyDescriptionSeverityWeakness

Frequently Asked Questions

1

What is the vulnerability ID for this issue?

The vulnerability ID for this issue is CVE-2023-40050.

2

What is the severity of CVE-2023-40050?

The severity of CVE-2023-40050 is critical with a CVSS score of 9.9.

3

What is the affected software for CVE-2023-40050?

The affected software for CVE-2023-40050 is Chef Automate versions prior to and including 4.10.29.

4

How can this vulnerability be exploited?

This vulnerability can be exploited by uploading a profile with a maliciously crafted content through the API or user interface in Chef Automate.

5

How can I fix CVE-2023-40050?

To fix CVE-2023-40050, update to a version of Chef Automate that is newer than 4.10.29.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203