CVE-2016-4326: Critical severity chef manage vulnerability
Published Jun 10, 2016
·Updated
The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
Affected Software
1 affected component
Chef Chef Manage<=1.11.4
Event History
Jun 10, 2016
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-4326?
CVE-2016-4326 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2016-4326?
To fix CVE-2016-4326, upgrade Chef Manage to version 1.12.0 or later.
3
What systems are affected by CVE-2016-4326?
CVE-2016-4326 affects Chef Manage versions prior to 1.12.0.
4
Can CVE-2016-4326 be exploited remotely?
Yes, CVE-2016-4326 can be exploited remotely by attackers through crafted serialized data in a cookie.
5
What is the impact of CVE-2016-4326?
The impact of CVE-2016-4326 is the potential for arbitrary code execution, which can compromise the affected system.