CVE-2010-5142

Chef < 0.9.0 - Authenticated User Account Management via Unrestricted API Endpoint

Title source: llm
STIX 2.1

Description

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

References (2)

Core 2

Scores

EPSS 0.0039
EPSS Percentile 60.2%

Details

CWE
CWE-264
Status published
Products (13)
opscode/chef 0.7.2
opscode/chef 0.7.4
opscode/chef 0.7.6
opscode/chef 0.7.8
opscode/chef 0.7.10
opscode/chef 0.7.12
opscode/chef 0.7.14
opscode/chef 0.8.2
opscode/chef 0.8.4
opscode/chef 0.8.6
... and 3 more
Published Aug 08, 2012
Tracked Since Feb 18, 2026