chef records
6 published records for vendor chef.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 50%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2025-8868Proof of concept | Chef Automate compliance service SQL Injection Vulnerabilitychef · automate · CWE-89 | High8.8 | — | 24.3% | Sep 29, 2025 |
40Plan | CVE-2016-4326No exploit | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialchef · chef manage | Critical9.8 | — | 4.2% | Jun 9, 2016 |
35Monitor | CVE-2023-40050No exploit | Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Applicationchef · automate · CWE-94 | High8.8 | — | 1.2% | Oct 31, 2023 |
35Monitor | CVE-2025-6724No exploit | Chef Automate SQL Injection Vulnerabilitychef · automate · CWE-89 | High8.8 | — | 0.4% | Sep 29, 2025 |
31Monitor | CVE-2015-8559No exploit | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.chef · chef · CWE-200 | High7.5 | — | 1.9% | Sep 21, 2017 |
31Monitor | CVE-2023-42658No exploit | InSpec Archive Command Vulnerable to Maliciously Crafted Profilechef · inspec · CWE-94 | High7.8 | — | 0.3% | Oct 31, 2023 |
- CVE-2025-886842Plan
Chef Automate compliance service SQL Injection Vulnerability
HighCVSS 8.8Proof of conceptEPSS 24%chef · automateSep 29, 2025
- CVE-2016-432640Plan
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serial
CriticalCVSS 9.8No exploitEPSS 4%chef · chef manageJun 9, 2016
- CVE-2023-4005035Monitor
Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application
HighCVSS 8.8No exploitEPSS 1%chef · automateOct 31, 2023
- CVE-2025-672435Monitor
Chef Automate SQL Injection Vulnerability
HighCVSS 8.8No exploitEPSS 0%chef · automateSep 29, 2025
- CVE-2015-855931Monitor
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
HighCVSS 7.5No exploitEPSS 2%chef · chefSep 21, 2017
- CVE-2023-4265831Monitor
InSpec Archive Command Vulnerable to Maliciously Crafted Profile
HighCVSS 7.8No exploitEPSS 0%chef · inspecOct 31, 2023