CVE-2022-42717

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:hashicorp:vagrant:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

08 Aug 2023, 14:21

Type Values Removed Values Added
CWE CWE-269 NVD-CWE-Other

18 Oct 2022, 18:00

Type Values Removed Values Added
First Time Linux
Hashicorp vagrant
Linux linux Kernel
CPE cpe:2.3:a:hashicorp:packer:*:*:*:*:*:*:*:* cpe:2.3:a:hashicorp:vagrant:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

14 Oct 2022, 19:19

Type Values Removed Values Added
First Time Hashicorp
Hashicorp packer
CPE cpe:2.3:a:hashicorp:packer:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CWE CWE-269
References (MISC) https://github.com/hashicorp/vagrant/pull/12910 - (MISC) https://github.com/hashicorp/vagrant/pull/12910 - Patch, Third Party Advisory
References (MISC) https://discuss.hashicorp.com/t/hcsec-2022-23-vagrant-nfs-sudoers-configuration-allows-for-local-privilege-escalation/45423 - (MISC) https://discuss.hashicorp.com/t/hcsec-2022-23-vagrant-nfs-sudoers-configuration-allows-for-local-privilege-escalation/45423 - Vendor Advisory
References (MISC) https://www.vagrantup.com/docs/synced-folders/nfs - (MISC) https://www.vagrantup.com/docs/synced-folders/nfs - Product

11 Oct 2022, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-10-11 23:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-42717

Mitre link : CVE-2022-42717

CVE.ORG link : CVE-2022-42717


JSON object : View

Products Affected

linux

  • linux_kernel

hashicorp

  • vagrant