Show filters
20 Total Results
Displaying 1-10 of 20
Sort by:
Attacker Value
Unknown

CVE-2024-9825

Disclosure Date: October 28, 2024 (last updated October 29, 2024)
The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token.  Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package. The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
0
Attacker Value
Unknown

CVE-2023-39155

Disclosure Date: July 26, 2023 (last updated October 08, 2023)
Jenkins Chef Identity Plugin 2.0.3 and earlier does not mask the user.pem key form field, increasing the potential for attackers to observe and capture it.
Attacker Value
Unknown

CVE-2023-28864

Disclosure Date: July 17, 2023 (last updated October 08, 2023)
Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.
Attacker Value
Unknown

CVE-2022-25209

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
Jenkins Chef Sinatra Plugin 1.20 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
Attacker Value
Unknown

CVE-2022-25208

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A missing permission check in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers with Overall/Read permission to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
Attacker Value
Unknown

CVE-2022-25207

Disclosure Date: February 15, 2022 (last updated February 23, 2025)
A cross-site request forgery (CSRF) vulnerability in Jenkins Chef Sinatra Plugin 1.20 and earlier allows attackers to have Jenkins send an HTTP request to an attacker-controlled URL and have it parse an XML response.
Attacker Value
Unknown

CVE-2021-27616

Disclosure Date: May 11, 2021 (last updated November 28, 2024)
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.
Attacker Value
Unknown

CVE-2021-27614

Disclosure Date: May 11, 2021 (last updated February 22, 2025)
SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One on SAP HANA, allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behaviour of the application thereby highly impacting the integrity and availability of the application.
Attacker Value
Unknown

CVE-2021-27613

Disclosure Date: May 11, 2021 (last updated November 28, 2024)
Under certain conditions, SAP Business One Chef cookbook, version - 9.2, 9.3, 10.0, used to install SAP Business One, allows an attacker to exploit an insecure temporary folder for incoming & outgoing payroll data and to access information which would otherwise be restricted, which could lead to Information Disclosure and highly impact system confidentiality, integrity and availability.
Attacker Value
Unknown

CVE-2019-15532

Disclosure Date: August 26, 2019 (last updated November 27, 2024)
CyberChef before 8.31.2 allows XSS in core/operations/TextEncodingBruteForce.mjs.
0