CVE-2025-8868
🟠 Łataj w tym tygodniu
Nieprawidłowe neutralizowanie danych w Chef Automate pozwala uwierzytelnionemu atakującemu na dostęp do funkcji.
CVSS
9.8
EPSS
24.3%
Exploit
none
Vendor
chef
Opis źródłowy (NVD)
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 9.8 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 24.3% |
| Opublikowano (NVD) | 2025-09-29 12:15:49 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-09 09:10:00 UTC |
Referencje