NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16351  CVE-2010-5142  chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.    6.5  Medium  2017-01-18  2012-08-13  View
11357  CVE-2011-5097  chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.    5.5  Medium  2017-01-07  2012-08-13  View
11358  CVE-2011-5098  chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.    6.5  Medium  2017-01-07  2012-08-10  View
87565  CVE-2017-1000026  Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using .. in tar archive entries          2017-07-18  2017-07-17  View
67357  CVE-2005-1632  Cheetah 0.9.15 and 0.9.16 searches the /tmp directory for modules before using the paths in the PYTHONPATH variable, which allows local users to execute arbitrary code via a malicious module in /tmp/.    7.2  High  2017-01-03  2008-09-05  View

Page 15302 of 17672, showing 5 records out of 88360 total, starting on record 76506, ending on 76510

Actions