InSpec Archive Command Vulnerable to Maliciously Crafted Profile
CVE-2023-42658
8.8HIGH
What is CVE-2023-42658?
A vulnerability in Chef InSpec allows attackers to execute arbitrary local commands through a specially crafted profile. This security flaw affects versions prior to 4.56.58 and 5.22.29, enabling potential exploitation that could compromise the integrity of the system. Users are advised to upgrade to secure versions and follow best cybersecurity practices to mitigate risks.
Affected Version(s)
Chef InSpec Windows 4.0.0
Chef InSpec Windows 4.0.0 < 4.56.58
Chef InSpec Windows 5.0.0 < 5.22.29