CVE-2010-5142 Information
Feb 14, 2021
cve
Description
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create destroy and update methods which allows remote authenticated users to manage user accounts via requests to the /users URI.
Reference
http://tickets.opscode.com/browse/CHEF-1289 https://github.com/opscode/chef/commit/c3bb41f727fbe00e5de719d687757b24c8dcdfc8
Share on: