Upload profile either
through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
check command with maliciously crafted profile allows remote code execution.
References
Link | Resource |
---|---|
https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Automate-CVE-2023-40050 | Vendor Advisory |
https://docs.chef.io/automate/profiles/ | Product |
https://docs.chef.io/release_notes_automate/ | Release Notes |
https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Automate-CVE-2023-40050 | Vendor Advisory |
https://docs.chef.io/automate/profiles/ | Product |
https://docs.chef.io/release_notes_automate/ | Release Notes |
Configurations
History
No history.
Information
Published : 2023-10-31 15:15
Updated : 2024-11-21 08:18
NVD link : CVE-2023-40050
Mitre link : CVE-2023-40050
CVE.ORG link : CVE-2023-40050
JSON object : View
Products Affected
chef
- automate