Beveiligingsadvies

CVE-2025-8868

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-09-29 11:29:50
Laatst bijgewerkt 2025-09-29 12:55:02
Toegewezen door ProgressSoftware
CVSS-score 9.8
Status PUBLISHED

Beschrijving

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.