Back

MEDIUM

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI

Published Aug 8, 2012

Description

chef-server-api/app/controllers/users.rb in the API in Chef before 0.9.0 does not require administrative privileges for the create, destroy, and update methods, which allows remote authenticated users to manage user accounts via requests to the /users URI.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 8, 2012
Updated Sep 16, 2024
Reserved Aug 8, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-F68M-Q26R-64F6