CVE-2011-5098: Medium severity chef vulnerability
chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5098?
CVE-2011-5098 is classified as a medium severity vulnerability due to its potential to allow unauthorized administrative access.
How do I fix CVE-2011-5098?
To fix CVE-2011-5098, upgrade to Chef version 0.9.20 or later, or 0.10.6 or later.
Who is affected by CVE-2011-5098?
CVE-2011-5098 affects all versions of Chef prior to 0.9.20 and 0.10.x before 0.10.6.
What type of vulnerability is CVE-2011-5098?
CVE-2011-5098 is an authorization bypass vulnerability that allows remote authenticated users to create admin clients.
What are the risks associated with CVE-2011-5098?
The risk associated with CVE-2011-5098 is that unauthorized users could gain administrative privileges, compromising the security of the Chef Server.