Upload profile either
through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
check command with maliciously crafted profile allows remote code execution.
References
Link | Resource |
---|---|
https://docs.chef.io/automate/profiles/ | Product |
https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Automate-CVE-2023-40050 | Vendor Advisory |
https://docs.chef.io/release_notes_automate/ | Release Notes |
Configurations
History
08 Nov 2023, 17:34
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://docs.chef.io/release_notes_automate/ - Release Notes | |
References | (MISC) https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Automate-CVE-2023-40050 - Vendor Advisory | |
References | (MISC) https://docs.chef.io/automate/profiles/ - Product | |
First Time |
Chef
Chef automate |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
CPE | cpe:2.3:a:chef:automate:*:*:*:*:*:*:*:* | |
CWE | CWE-94 |
31 Oct 2023, 15:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-31 15:15
Updated : 2023-11-08 17:34
NVD link : CVE-2023-40050
Mitre link : CVE-2023-40050
JSON object : View
Products Affected
chef
- automate
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')