HIGH 7.8 Microsoft

CVE-2022-42717

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

Microsoft Security Update 2022-Oct: An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

Affected Products

References

Published: 2022-10-11 · Source: Microsoft · Feed updated: 2026-09-03
This high severity vulnerability with a CVSS score of 7.8 was published on 2022-10-11 via Microsoft. Affected: cbl2 packer 1.8.7-1 on CBL Mariner 2.0.
vulnfeed aggregates 9119 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.