Записи chef
6 опубликованных записей вендора chef.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 1
- С записью об исправлении
- 50 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2025-8868Proof of concept | Chef Automate compliance service SQL Injection Vulnerabilitychef · automate · CWE-89 | Высокая8,8 | — | 24,3 % | 29 сент. 2025 г. |
40В плане | CVE-2016-4326Эксплойта нет | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialchef · chef manage | Критическая9,8 | — | 4,2 % | 9 июн. 2016 г. |
35Наблюдать | CVE-2023-40050Эксплойта нет | Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Applicationchef · automate · CWE-94 | Высокая8,8 | — | 1,2 % | 31 окт. 2023 г. |
35Наблюдать | CVE-2025-6724Эксплойта нет | Chef Automate SQL Injection Vulnerabilitychef · automate · CWE-89 | Высокая8,8 | — | 0,4 % | 29 сент. 2025 г. |
31Наблюдать | CVE-2015-8559Эксплойта нет | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.chef · chef · CWE-200 | Высокая7,5 | — | 1,9 % | 21 сент. 2017 г. |
31Наблюдать | CVE-2023-42658Эксплойта нет | InSpec Archive Command Vulnerable to Maliciously Crafted Profilechef · inspec · CWE-94 | Высокая7,8 | — | 0,3 % | 31 окт. 2023 г. |
- CVE-2025-886842В плане
Chef Automate compliance service SQL Injection Vulnerability
ВысокаяCVSS 8,8Proof of conceptEPSS 24 %chef · automate29 сент. 2025 г.
- CVE-2016-432640В плане
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serial
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %chef · chef manage9 июн. 2016 г.
- CVE-2023-4005035Наблюдать
Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %chef · automate31 окт. 2023 г.
- CVE-2025-672435Наблюдать
Chef Automate SQL Injection Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %chef · automate29 сент. 2025 г.
- CVE-2015-855931Наблюдать
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %chef · chef21 сент. 2017 г.
- CVE-2023-4265831Наблюдать
InSpec Archive Command Vulnerable to Maliciously Crafted Profile
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %chef · inspec31 окт. 2023 г.