Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7fj6-6m8r-4v8h

Опубликовано: 31 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 9.9

Описание

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

EPSS

Процентиль: 93%
0.09887
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-434
CWE-94

Связанные уязвимости

CVSS3: 9.9
nvd
больше 2 лет назад

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

EPSS

Процентиль: 93%
0.09887
Низкий

9.9 Critical

CVSS3

Дефекты

CWE-434
CWE-94