chef Vulnerabilities and Affected Products
Vulnerabilities associated with automate.
Products
Clear product- automate2 vulnerabilities
- chef_manage1 vulnerability
- inspec1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-8868CRITICAL | Chef Automate compliance service SQL Injection VulnerabilityIn Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token. | CVSS9.8v3.1 | EPSS22.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-40050CRITICAL | Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance ApplicationUpload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution. | CVSS9.9v3.1 | EPSS1.18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |