Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: ProgressSoftware

Published: 2023-10-31T14:07:59.881Z

Updated: 2023-10-31T14:07:59.881Z

Reserved: 2023-08-08T19:44:41.112Z


Link: CVE-2023-40050

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-10-31T15:15:09.227

Modified: 2023-11-08T17:34:25.577


Link: CVE-2023-40050

JSON object: View

cve-icon Redhat Information

No data.