CVE-2010-5142
Chef < 0.9.0 - Authenticated User Account Management via Unrestricted API Endpoint
Title source: llmDescription
chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.
References (2)
Core 2
Core References
Patch x_refsource_confirm
https://github.com/opscode/chef/commit/c3bb41f727fbe00e5de719d687757b24c8dcdfc8
Various Sources x_refsource_confirm
http://tickets.opscode.com/browse/CHEF-1289
Scores
EPSS
0.0039
EPSS Percentile
60.2%
Details
CWE
CWE-264
Status
published
Products (13)
opscode/chef
0.7.2
opscode/chef
0.7.4
opscode/chef
0.7.6
opscode/chef
0.7.8
opscode/chef
0.7.10
opscode/chef
0.7.12
opscode/chef
0.7.14
opscode/chef
0.8.2
opscode/chef
0.8.4
opscode/chef
0.8.6
... and 3 more
Published
Aug 08, 2012
Tracked Since
Feb 18, 2026