Vulnerabilities (CVE)

Filtered by vendor Chef Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42658 1 Chef 1 Inspec 2024-11-21 N/A 8.8 HIGH
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
CVE-2023-40050 1 Chef 1 Automate 2024-11-21 N/A 9.9 CRITICAL
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
CVE-2016-4326 1 Chef 1 Chef Manage 2024-11-21 7.5 HIGH 9.8 CRITICAL
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
CVE-2015-8559 1 Chef 1 Chef 2024-11-21 5.0 MEDIUM 7.5 HIGH
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.