Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q923-fjjc-9frg

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.

chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.

EPSS

Процентиль: 41%
0.00191
Низкий

Связанные уязвимости

ubuntu
больше 13 лет назад

chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.

nvd
больше 13 лет назад

chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.

debian
больше 13 лет назад

chef-server-api/app/controllers/clients.rb in Chef Server in Chef befo ...

EPSS

Процентиль: 41%
0.00191
Низкий