Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
BID:54953
Info
Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
| Bugtraq ID: | 54953 |
| Class: | Access Validation Error |
| CVE: |
CVE-2010-5142 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 07 2010 12:00AM |
| Updated: | Jun 07 2010 12:00AM |
| Credit: | Thom May |
| Vulnerable: |
OPSCODE Chef 0.8.16 OPSCODE Chef 0.8.8 |
| Not Vulnerable: |
OPSCODE Chef 0.9 |
Discussion
Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
Chef is prone to multiple security-bypass vulnerabilities that may allow attackers to perform actions without proper authorization.
Attackers can exploit these issues to bypass security restrictions and perform unauthorized actions such as managing user accounts.
Chef versions prior to 0.9.0 are vulnerable.
Chef is prone to multiple security-bypass vulnerabilities that may allow attackers to perform actions without proper authorization.
Attackers can exploit these issues to bypass security restrictions and perform unauthorized actions such as managing user accounts.
Chef versions prior to 0.9.0 are vulnerable.
Exploit / POC
Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
Solution:
Updates are available. Please see the references for more details.
Solution:
Updates are available. Please see the references for more details.
References
Chef CVE-2010-5142 Multiple Security Bypass Vulnerabilities
References:
References: