Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2010-5142

около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

CVSS2: 6.5
EPSS: Низкий
nvd логотип

CVE-2010-5142

около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

CVSS2: 6.5
EPSS: Низкий
debian логотип

CVE-2010-5142

около 14 лет назад

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9 ...

CVSS2: 6.5
EPSS: Низкий
github логотип

GHSA-f68m-q26r-64f6

около 4 лет назад

Chef Improper Access Control vulnerability

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2010-5142

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

CVSS2: 6.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2010-5142

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

CVSS2: 6.5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2010-5142

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9 ...

CVSS2: 6.5
2%
Низкий
около 14 лет назад
github логотип
GHSA-f68m-q26r-64f6

Chef Improper Access Control vulnerability

2%
Низкий
около 4 лет назад

Уязвимостей на страницу