Known Vulnerabilities for products from Chef
Listed below are 4 of the newest known vulnerabilities associated with the vendor "Chef".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-8668 json | Not Provided | 2026-06-18 | 2026-06-22 | |
| CVE-2026-8100 json | Not Provided | 2026-06-18 | 2026-06-22 | |
| CVE-2023-42658 json | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile. | 7.8 - HIGH | 2023-10-31 | 2023-11-08 |
| CVE-2023-40050 json | Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec chec... | 8.8 - HIGH | 2023-10-31 | 2023-11-08 |
| CVE-2016-4326 json | The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via... | Not Provided | 2016-06-10 | 2026-05-06 |
| CVE-2015-8559 json | The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/m... | 7.5 - HIGH | 2017-09-21 | 2021-06-28 |
Known software with vulnerabilities from Chef
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Chef | Chef | 0.0.1 |
| Application | Chef | Chef Manage | 1.11.4 |