Showing 2 vulnerabilities on this page for automate

Signals CISA KEV Ransomware Nuclei
chef vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Chef Automate compliance service SQL Injection Vulnerability

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

CWE-200CWE-89Sep 29, 20251 related artifact
CVSS9.8v3.1EPSS22.8%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Automate Vulnerable to Malicious Content Uploaded Through Embedded Compliance Application

Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.

CWE-434CWE-94Oct 31, 2023
CVSS9.9v3.1EPSS1.18%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX