Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application
CVE-2023-40050
9.9CRITICAL
What is CVE-2023-40050?
A vulnerability exists in Chef Automate, allowing remote code execution due to the ability to upload a maliciously crafted profile via the API or user interface. This affects versions prior to and including 4.10.29, where executing a check command in InSpec can lead to unauthorized access and exploitation of system resources.
Affected Version(s)
Chef Automate Linux 4.0.0 <= 4.10.29