Vulnerabilities (CVE)

Filtered by vendor Chef Subscribe
Total 4 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-42658 1 Chef 1 Inspec 2023-12-10 N/A 7.8 HIGH
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
CVE-2023-40050 1 Chef 1 Automate 2023-12-10 N/A 8.8 HIGH
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
CVE-2015-8559 1 Chef 1 Chef 2023-12-10 5.0 MEDIUM 7.5 HIGH
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
CVE-2016-4326 1 Chef 1 Chef Manage 2023-12-10 7.5 HIGH 9.8 CRITICAL
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.