CVE-2023-42658: InSpec Archive Command Vulnerable to Maliciously Crafted Profile
Published Oct 31, 2023
·Updated
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
Affected Software
2 affected components
Chef InSpec<4.56.58
Chef InSpec>=5.0.0<5.22.29
Remediation
Information
Solution (optional): Customers should adopt the latest releases of InSpec on the 4, 5, and 6 supported versions available from the community and customer downloads portals.
Event History
Oct 31, 2023
CVE Published
02:08 PM
Data Sourced
02:08 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-42658?
CVE-2023-42658 is a vulnerability in Chef InSpec that allows for local command execution through a maliciously crafted profile.
2
What is the severity of CVE-2023-42658?
CVE-2023-42658 has a severity rating of 8.8, which is considered high.
3
How does CVE-2023-42658 affect Chef InSpec?
CVE-2023-42658 affects Chef InSpec versions prior to 4.56.58 and 5.22.29.
4
How can I fix CVE-2023-42658?
To fix CVE-2023-42658, update Chef InSpec to version 4.56.58 or newer (if using version 4.x) or version 5.22.29 or newer (if using version 5.x).
5
Where can I find more information about CVE-2023-42658?
You can find more information about CVE-2023-42658 in the release notes of Chef InSpec, the Chef InSpec CLI documentation, and a product alert bulletin.