Описание
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
Ссылки
- Vendor Advisory
- Product
- Release Notes
- Vendor Advisory
- Product
- Release Notes
Уязвимые конфигурации
Конфигурация 1Версия до 4.10.29 (включая)
cpe:2.3:a:chef:automate:*:*:*:*:*:*:*:*
EPSS
Процентиль: 93%
0.09887
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-94
CWE-94
Связанные уязвимости
CVSS3: 9.9
github
больше 2 лет назад
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
EPSS
Процентиль: 93%
0.09887
Низкий
9.9 Critical
CVSS3
8.8 High
CVSS3
Дефекты
CWE-94
CWE-94