chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:12

Updated: 2022-10-03T16:15:12

Reserved: 2022-10-03T00:00:00


Link: CVE-2011-5097

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-08-08T10:26:18.173

Modified: 2012-08-13T04:00:00.000


Link: CVE-2011-5097

JSON object: View

cve-icon Redhat Information

No data.

CWE