Show filters
20 Total Results
Displaying 11-20 of 20
Sort by:
Attacker Value
Unknown
CVE-2019-1003086
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2019-1003087
Disclosure Date: April 04, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Chef Sinatra Plugin in the ChefBuilderConfiguration.DescriptorImpl#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
0
Attacker Value
Unknown
CVE-2015-8559
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
0
Attacker Value
Unknown
CVE-2016-6594
Disclosure Date: June 08, 2017 (last updated November 26, 2024)
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.
0
Attacker Value
Unknown
CVE-2017-7174
Disclosure Date: March 17, 2017 (last updated November 26, 2024)
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
0
Attacker Value
Unknown
CVE-2016-4326
Disclosure Date: June 10, 2016 (last updated November 25, 2024)
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
0
Attacker Value
Unknown
CVE-2014-5623
Disclosure Date: September 09, 2014 (last updated October 05, 2023)
The penguinchefshop (aka com.freegames.penguinchefshop) application 1.0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2011-5098
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.
0
Attacker Value
Unknown
CVE-2010-5142
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.
0
Attacker Value
Unknown
CVE-2011-5097
Disclosure Date: August 08, 2012 (last updated October 04, 2023)
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
0