CVE-2015-8559: Infoleak
Published Sep 21, 2017
·Updated
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
Affected Software
1 affected component
Chef chef<15.4.45
Remediation
Patch Available
Event History
Sep 21, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-8559?
CVE-2015-8559 is considered a high severity vulnerability due to the exposure of the private RSA key.
2
How do I fix CVE-2015-8559?
To fix CVE-2015-8559, upgrade the Chef Infra Client to version 15.4.45 or later.
3
What software is affected by CVE-2015-8559?
CVE-2015-8559 affects Chef Infra Client versions prior to 15.4.45.
4
What data is compromised in CVE-2015-8559?
CVE-2015-8559 leads to the leakage of the validator.pem private RSA key to /var/log/messages.
5
What impact does CVE-2015-8559 have on security?
The impact of CVE-2015-8559 can lead to unauthorized access to systems using the exposed private RSA key.