Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown

CVE-2019-1003086

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown

CVE-2019-1003087

Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
Attacker Value
Unknown

CVE-2015-8559

Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
Attacker Value
Unknown

CVE-2016-6594

Disclosure Date: June 08, 2017 (last updated November 26, 2024)
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
0
Attacker Value
Unknown

CVE-2017-7174

Disclosure Date: March 17, 2017 (last updated November 26, 2024)
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
0
Attacker Value
Unknown

CVE-2016-4326

Disclosure Date: June 10, 2016 (last updated November 25, 2024)
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
0
Attacker Value
Unknown

CVE-2014-5623

Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2011-5098

Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.
0
Attacker Value
Unknown

CVE-2010-5142

Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.
0
Attacker Value
Unknown

CVE-2011-5097

Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
0