VU#586503Third-party advisory
http://www.kb.cert.org/vuls/id/586503 CVE-2016-4326
CRITICAL
Chef Manage Add-on before 1.12.0 for Chef Crafted Serialized Data Vulnerability
Record summary
CVE-2016-4326 has a selected CVSS score of 9.8 (critical).
Description
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 10, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
chef_manageBrowse chef / chef_manage | VulnCheck | Version data not supplied | |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-4326