High severity8.8NVD Advisory· Published Oct 31, 2023· Updated Jun 17, 2026
CVE-2023-42658
CVE-2023-42658
Description
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
Affected products
4<4.56.58 and <5.22.29+ 1 more
- (no CPE)range: <4.56.58 and <5.22.29
- (no CPE)range: 4.0.0
Patches
Vulnerability mechanics
References
3- community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Inspec-CVE-2023-42658nvdVendor Advisory
- docs.chef.io/inspec/cli/nvdVendor Advisory
- docs.chef.io/release_notes_inspec/nvdRelease NotesVendor Advisory
News mentions
0No linked articles in our index yet.