CVE-2011-5097
- EPSS 0.39%
- Veröffentlicht 08.08.2012 10:26:18
- Zuletzt bearbeitet 11.04.2025 00:51:21
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbook...
CVE-2011-5098
- EPSS 0.19%
- Veröffentlicht 08.08.2012 10:26:18
- Zuletzt bearbeitet 11.04.2025 00:51:21
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restri...
CVE-2010-5142
- EPSS 0.39%
- Veröffentlicht 08.08.2012 10:26:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /user...