Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2010-5142

Опубликовано: 08 авг. 2012
Источник: debian
EPSS Низкий

Описание

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cheffixed0.10.10-1package

EPSS

Процентиль: 60%
0.00391
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

nvd
больше 13 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

github
больше 3 лет назад

Chef Improper Access Control vulnerability

EPSS

Процентиль: 60%
0.00391
Низкий