chef kayıtları
chef üreticisine ait 6 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %50
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWESaldırı profili
Tüm kayıtlar
6 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2025-8868Kavram kanıtı | Chef Automate compliance service SQL Injection Vulnerabilitychef · automate · CWE-89 | Yüksek8,8 | — | %24,3 | 29 Eyl 2025 |
40Planlayın | CVE-2016-4326İstismar yok | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialchef · chef manage | Kritik9,8 | — | %4,2 | 9 Haz 2016 |
35İzleyin | CVE-2023-40050İstismar yok | Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Applicationchef · automate · CWE-94 | Yüksek8,8 | — | %1,2 | 31 Eki 2023 |
35İzleyin | CVE-2025-6724İstismar yok | Chef Automate SQL Injection Vulnerabilitychef · automate · CWE-89 | Yüksek8,8 | — | %0,4 | 29 Eyl 2025 |
31İzleyin | CVE-2015-8559İstismar yok | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.chef · chef · CWE-200 | Yüksek7,5 | — | %1,9 | 21 Eyl 2017 |
31İzleyin | CVE-2023-42658İstismar yok | InSpec Archive Command Vulnerable to Maliciously Crafted Profilechef · inspec · CWE-94 | Yüksek7,8 | — | %0,3 | 31 Eki 2023 |
- CVE-2025-886842Planlayın
Chef Automate compliance service SQL Injection Vulnerability
YüksekCVSS 8,8Kavram kanıtıEPSS %24chef · automate29 Eyl 2025
- CVE-2016-432640Planlayın
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serial
KritikCVSS 9,8İstismar yokEPSS %4chef · chef manage9 Haz 2016
- CVE-2023-4005035İzleyin
Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application
YüksekCVSS 8,8İstismar yokEPSS %1chef · automate31 Eki 2023
- CVE-2025-672435İzleyin
Chef Automate SQL Injection Vulnerability
YüksekCVSS 8,8İstismar yokEPSS %0chef · automate29 Eyl 2025
- CVE-2015-855931İzleyin
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
YüksekCVSS 7,5İstismar yokEPSS %2chef · chef21 Eyl 2017
- CVE-2023-4265831İzleyin
InSpec Archive Command Vulnerable to Maliciously Crafted Profile
YüksekCVSS 7,8İstismar yokEPSS %0chef · inspec31 Eki 2023