Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f68m-q26r-64f6

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью

Описание

Chef Improper Access Control vulnerability

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

Пакеты

Наименование

chef

rubygems
Затронутые версииВерсия исправления

< 0.9.0

0.9.0

EPSS

Процентиль: 73%
0.0157
Низкий

Дефекты

CWE-284

Связанные уязвимости

ubuntu
около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

nvd
около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

debian
около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9 ...

EPSS

Процентиль: 73%
0.0157
Низкий

Дефекты

CWE-284