CVE-2025-6724: Chef Automate SQL Injection Vulnerability
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6724?
CVE-2025-6724 is rated as a high severity vulnerability due to the potential for authenticated attackers to access restricted functionalities.
How do I fix CVE-2025-6724?
To fix CVE-2025-6724, upgrade to Chef Automate version 4.13.295 or later.
What types of systems are affected by CVE-2025-6724?
CVE-2025-6724 affects Chef Automate versions earlier than 4.13.295 running on Linux x86 platforms.
What can an attacker do exploit CVE-2025-6724?
An attacker can exploit CVE-2025-6724 to gain unauthorized access to restricted functionalities in multiple services via SQL injection.
Is authentication required to exploit CVE-2025-6724?
Yes, CVE-2025-6724 requires the attacker to be authenticated to exploit the vulnerability.