chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:15:12

Updated: 2022-10-03T16:15:12

Reserved: 2022-10-03T00:00:00


Link: CVE-2011-5098

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2012-08-08T10:26:18.207

Modified: 2012-08-10T04:00:00.000


Link: CVE-2011-5098

JSON object: View

cve-icon Redhat Information

No data.

CWE