CVE-2010-5142
Summary
| CVE | CVE-2010-5142 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-08 10:26:17 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:S/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Opscode | Chef | 0.7.10 | All | All | All |
| Application | Opscode | Chef | 0.7.12 | All | All | All |
| Application | Opscode | Chef | 0.7.14 | All | All | All |
| Application | Opscode | Chef | 0.7.2 | All | All | All |
| Application | Opscode | Chef | 0.7.4 | All | All | All |
| Application | Opscode | Chef | 0.7.6 | All | All | All |
| Application | Opscode | Chef | 0.7.8 | All | All | All |
| Application | Opscode | Chef | 0.8.2 | All | All | All |
| Application | Opscode | Chef | 0.8.4 | All | All | All |
| Application | Opscode | Chef | 0.8.6 | All | All | All |
| Application | Opscode | Chef | 0.8.8 | All | All | All |
| Application | Opscode | Chef | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [#CHEF-1289] API does not check for admin rights for user management - Opscode Open Source Ticket Tracking | af854a3a-2127-422b-91ae-364da2661108 | tickets.opscode.com | |
| CHEF-1289 API does not check for admin rights for user management · chef/chef@c3bb41f · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997218 Rubygems (Rubygems) Security Update for chef (GHSA-f68m-q26r-64f6)