CVE-2011-5097

chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.4:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.6:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.8:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.10:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.12:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.14:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.8:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.10:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.0:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.2:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.4:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.12:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.9.14:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2012-08-08 10:26

Updated : 2024-02-28 12:00


NVD link : CVE-2011-5097

Mitre link : CVE-2011-5097

CVE.ORG link : CVE-2011-5097


JSON object : View

Products Affected

opscode

  • chef
CWE
CWE-264

Permissions, Privileges, and Access Controls