CVE-2025-8868: Chef Automate compliance service SQL Injection Vulnerability
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via
improperly neutralized inputs used in an SQL command using a well-known token.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8868?
CVE-2025-8868 is considered a high severity vulnerability due to its potential for unauthorized access to restricted functionality.
How do I fix CVE-2025-8868?
To fix CVE-2025-8868, upgrade Chef Automate to version 4.13.295 or higher.
What causes CVE-2025-8868?
CVE-2025-8868 is caused by improperly neutralized inputs in an SQL command, allowing authenticated attackers to exploit the compliance service.
Who is affected by CVE-2025-8868?
CVE-2025-8868 affects all versions of Chef Automate prior to 4.13.295 on Linux x86 platforms.
What should I do if I cannot upgrade to mitigate CVE-2025-8868?
If you cannot upgrade, limit access to the Chef Automate system and monitor for any suspicious activities as a temporary measure.