Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2010-5142

Опубликовано: 08 авг. 2012
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*
Версия до 0.8.10 (включая)
cpe:2.3:a:opscode:chef:0.7.2:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.4:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.6:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.8:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.10:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.12:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.7.14:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.2:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.4:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.6:*:*:*:*:*:*:*
cpe:2.3:a:opscode:chef:0.8.8:*:*:*:*:*:*:*

EPSS

Процентиль: 60%
0.00391
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
больше 13 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

debian
больше 13 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9 ...

github
больше 3 лет назад

Chef Improper Access Control vulnerability

EPSS

Процентиль: 60%
0.00391
Низкий

6.5 Medium

CVSS2

Дефекты

CWE-264