← Back

CVE-2022-42717

nvd nist
Published: Oct 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

Affected (1)

Products: Hashicorp: Vagrant
1 product
Vagrant
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 2.3.1
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (6)

Timeline

No history available yet.