← Back to browse · API

CVE-2023-40050

Severity
CRITICAL
CVSS
9.9
EPSS
0.01184
Risk score
40.01
CISA KEV
No
PoC
No
Published
2023-10-31
Modified
2024-09-06
First seen
2026-08-07
Aliases
EUVD-2023-44657, GHSA-7FJ6-6M8R-4V8H
Products
Progress Software:Chef Automate 4.0.0 ≤4.10.29
Sources
euvd EUVD-2023-44657

Description

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

References