Filtered by vendor Chef
Subscribe
Total
4 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2023-42658 | 1 Chef | 1 Inspec | 2024-11-21 | N/A | 8.8 HIGH |
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile. | |||||
CVE-2023-40050 | 1 Chef | 1 Automate | 2024-11-21 | N/A | 9.9 CRITICAL |
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution. | |||||
CVE-2016-4326 | 1 Chef | 1 Chef Manage | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie. | |||||
CVE-2015-8559 | 1 Chef | 1 Chef | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages. |