CVE-2011-5097
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
chef-server-api/app/controllers/cookbooks.rb en Chef Server en Chef anterior a v0.9.18, y v0.10.x anterior a v0.10.2, no requiere privilegios administrativos para actualizar y destruir métodos, lo que permite a usuarios remotos autenticados (1) subir (cookbooks) a través de un comando de subida de un (knife cookbook) o (2) eliminar (cookbooks) a través de un comando (knife cookbook) de borrado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-08-08 CVE Reserved
- 2012-08-08 CVE Published
- 2024-04-25 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://tickets.opscode.com/browse/CHEF-2436 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/opscode/chef/commit/a4ea6edab2fecb922f999cffb0daa04eeeec7a26 | 2012-08-13 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | <= 0.9.16 Search vendor "Opscode" for product "Chef" and version " <= 0.9.16" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.2 Search vendor "Opscode" for product "Chef" and version "0.7.2" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.4 Search vendor "Opscode" for product "Chef" and version "0.7.4" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.6 Search vendor "Opscode" for product "Chef" and version "0.7.6" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.8 Search vendor "Opscode" for product "Chef" and version "0.7.8" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.10 Search vendor "Opscode" for product "Chef" and version "0.7.10" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.12 Search vendor "Opscode" for product "Chef" and version "0.7.12" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.7.14 Search vendor "Opscode" for product "Chef" and version "0.7.14" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.8.2 Search vendor "Opscode" for product "Chef" and version "0.8.2" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.8.4 Search vendor "Opscode" for product "Chef" and version "0.8.4" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.8.6 Search vendor "Opscode" for product "Chef" and version "0.8.6" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.8.8 Search vendor "Opscode" for product "Chef" and version "0.8.8" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.8.10 Search vendor "Opscode" for product "Chef" and version "0.8.10" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.0 Search vendor "Opscode" for product "Chef" and version "0.9.0" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.2 Search vendor "Opscode" for product "Chef" and version "0.9.2" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.4 Search vendor "Opscode" for product "Chef" and version "0.9.4" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.6 Search vendor "Opscode" for product "Chef" and version "0.9.6" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.8 Search vendor "Opscode" for product "Chef" and version "0.9.8" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.10 Search vendor "Opscode" for product "Chef" and version "0.9.10" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.12 Search vendor "Opscode" for product "Chef" and version "0.9.12" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.9.14 Search vendor "Opscode" for product "Chef" and version "0.9.14" | - |
Affected
| ||||||
Opscode Search vendor "Opscode" | Chef Search vendor "Opscode" for product "Chef" | 0.10.0 Search vendor "Opscode" for product "Chef" and version "0.10.0" | - |
Affected
|