« Volver al listado

CVE-2023-42658

Estado: ModificadaAlta (7.8)—

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-42658",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-42658",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-06T15:43:59.488901Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@progress.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@progress.com",
      "affectedData": [
        {
          "repo": "https://github.com/inspec/inspec",
          "vendor": "Progress Software Corporation",
          "modules": [
            "InSpec Archive",
            "InSpec Check",
            "InSpec Export"
          ],
          "product": "Chef InSpec",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.56.58 ",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "5.0.0",
              "lessThan": "5.22.29",
              "versionType": "semver"
            }
          ],
          "platforms": [
            "Windows",
            "Linux",
            "MacOS"
          ],
          "packageName": "InSpec",
          "collectionURL": "https://community.chef.io/downloads/tools/inspec?os=windows",
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*"
          ],
          "vendor": "chef",
          "product": "inspec",
          "versions": [
            {
              "status": "affected",
              "version": "4.0",
              "lessThan": "4.56.58",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "5.0",
              "lessThan": "5.22.29",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.0",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2023-10-31T15:15:09.393",
  "references": [
    {
      "url": "https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Inspec-CVE-2023-42658",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://docs.chef.io/inspec/cli/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://docs.chef.io/release_notes_inspec/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "security@progress.com"
    },
    {
      "url": "https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Inspec-CVE-2023-42658",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.chef.io/inspec/cli/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://docs.chef.io/release_notes_inspec/",
      "tags": [
        "Release Notes",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@progress.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        },
        {
          "lang": "en",
          "value": "CWE-917"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "\nArchive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile."
    },
    {
      "lang": "es",
      "value": "El comando de archivo en Chef InSpec anteriores a 4.56.58 y 5.22.29 permite la ejecución de comandos locales a través de un perfil creado con fines malintencionados."
    }
  ],
  "lastModified": "2026-06-17T06:24:11.977",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F8BBB3EE-3009-4381-B417-702742CA2A14",
              "versionEndExcluding": "4.56.58"
            },
            {
              "criteria": "cpe:2.3:a:chef:inspec:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E1C87BF9-A413-4F80-8F0D-58778D58740C",
              "versionEndExcluding": "5.22.29",
              "versionStartIncluding": "5.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@progress.com"
}