Progress Software Chef Automate vulnerabilities
2 known vulnerabilities affecting progress_software/chef_automate.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2025-8868P1HIGHCVSS 8.8ExploitedPoCfixed in 4.13.2952025-09-29
CVE-2025-8868 [HIGH] CWE-89 CVE-2025-8868: In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated a
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via
improperly neutralized inputs used in an SQL command using a well-known token.
nvd
CVE-2025-6724P3HIGHCVSS 8.8fixed in 4.13.2952025-09-29
CVE-2025-6724 [HIGH] CWE-89 CVE-2025-6724: In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated a
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
nvd