CVE-2024-9825: The Chef Habitat builder is impacted by Indirect Object reference(IDOR) by deletion of personal access token

Published Oct 28, 2024
·
Updated

The Chef Habitat builder-api on-prem-builder package  with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token.  Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package.

The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.

Affected Software

1 affected component
Chef Habitat Builder API<habitat/builder-api/10315/20240913162802

Event History

Oct 28, 2024
CVE Published
via MITRE·06:42 PM
Data Sourced
via MITRE·06:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-9825?

CVE-2024-9825 is classified as a medium severity vulnerability.

2

How do I fix CVE-2024-9825?

To mitigate CVE-2024-9825, upgrade the Chef Habitat builder-api to version habitat/builder-api/10315/20240913162802 or higher.

3

Who is affected by CVE-2024-9825?

CVE-2024-9825 affects users of the Chef Habitat Builder API on versions lower than habitat/builder-api/10315/20240913162802.

4

What type of vulnerability is CVE-2024-9825?

CVE-2024-9825 is an indirect object reference (IDOR) vulnerability.

5

What can attackers do with CVE-2024-9825?

Attackers can exploit CVE-2024-9825 to delete personal tokens of unauthorized users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203