QID 997218
Date Published: 2024-02-12
QID 997218: Rubygems (Rubygems) Security Update for chef (GHSA-f68m-q26r-64f6)
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-f68m-q26r-64f6 for updates and patch information.
Vendor References
- GHSA-f68m-q26r-64f6 -
github.com/advisories/GHSA-f68m-q26r-64f6
CVEs related to QID 997218
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-f68m-q26r-64f6 | chef |
|