Логотип exploitDog
bind:CVE-2023-28864
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-28864

Количество 4

Количество 4

ubuntu логотип

CVE-2023-28864

больше 2 лет назад

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-28864

больше 2 лет назад

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-28864

больше 2 лет назад

Progress Chef Infra Server before 15.7 allows a local attacker to expl ...

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-7wj2-558x-h38c

больше 2 лет назад

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-28864

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-28864

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-28864

Progress Chef Infra Server before 15.7 allows a local attacker to expl ...

CVSS3: 5.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7wj2-558x-h38c

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a /var/opt/opscode/local-mode-cache/backup world-readable temporary backup path to access sensitive information, resulting in the disclosure of all indexed node data, because OpenSearch credentials are exposed. (The data typically includes credentials for additional systems.) The attacker must wait for an admin to run the "chef-server-ctl reconfigure" command.

CVSS3: 5.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу