CVE-2011-5097: Medium severity chef vulnerability
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5097?
CVE-2011-5097 has been assigned a severity rating of medium due to the potential for unauthorized cookbook uploads and deletions.
How do I fix CVE-2011-5097?
To fix CVE-2011-5097, upgrade Chef to version 0.9.18 or later, or 0.10.2 or later to ensure administrative privileges are enforced.
What versions of Chef are affected by CVE-2011-5097?
CVE-2011-5097 affects Chef versions up to 0.9.16 and 0.10.x prior to 0.10.2.
What is the impact of CVE-2011-5097 on system security?
The impact of CVE-2011-5097 allows remote authenticated users to modify or delete critical cookbooks without proper authorization.
Is it necessary to remove Chef completely to resolve CVE-2011-5097?
No, removing Chef is not necessary; simply upgrading to the patched versions will resolve CVE-2011-5097.