CVE-2023-40050
Upload profile either
through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
CRITICAL · CVSS 9.9
EPSS 0.17272
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 5% of all CVEs by exploitation likelihood
- CVSS base score ≥ 7.0
Sigma rules0
YARA rules0