Showing 2 vulnerabilities on this page for Chef Automate

Signals CISA KEV Ransomware Nuclei
Progress Software vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Chef Automate compliance service SQL Injection Vulnerability

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

CWE-200CWE-89Sep 29, 20251 related artifact
CVSS9.8v3.1EPSS22.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Chef Automate SQL Injection Vulnerability

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.

CWE-89Sep 29, 2025
CVSS8.8v3.1EPSS0.342%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX