Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-11115.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-11115
Upstream
Published
2022-10-11T23:15:10Z
Modified
2026-04-21T04:21:49.808579Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
CVE-2022-42717 affecting package packer for versions less than 1.8.7-1
Details

An issue was discovered in Hashicorp Packer before 2.3.1. The recommended sudoers configuration for Vagrant on Linux is insecure. If the host has been configured according to this documentation, non-privileged users on the host can leverage a wildcard in the sudoers configuration to execute arbitrary commands as root.

References

Affected packages

Azure Linux:2 / packer

Package

Name
packer
Purl
pkg:rpm/azure-linux/packer

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.7-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-11115.json"