In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
References
| Link | Resource |
|---|---|
| https://docs.chef.io/release_notes_automate/#4.13.295 | Patch |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2025-09-29 12:15
Updated : 2025-10-16 17:15
NVD link : CVE-2025-6724
Mitre link : CVE-2025-6724
CVE.ORG link : CVE-2025-6724
JSON object : View
Products Affected
linux
- linux_kernel
chef
- automate
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
