# CVE-2023-42658

## Summary

- **CVE ID:** CVE-2023-42658
- **Severity:** HIGH
- **CVSS Score:** 8.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-94, CWE-917
- **Published:** Oct 31, 2023
- **Last Modified:** Mar 13, 2026

## Description

Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.

## Affected Products

- Progress Software Corporation — Chef InSpec (4.0.0)
- Progress Software Corporation — Chef InSpec (5.0.0)

## References

- [CNA](https://docs.chef.io/release_notes_inspec/)
- [CNA](https://docs.chef.io/inspec/cli/)
- [CNA](https://community.progress.com/s/article/Product-Alert-Bulletin-October-2023-CHEF-Inspec-CVE-2023-42658)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.15%
- **EPSS Percentile:** 35.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._