PT-2025-39823 · Progress · Chef Automate

Published

2025-09-29

·

Updated

2025-10-05

·

CVE-2025-6724

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Chef Automate versions prior to 4.13.295
Description Chef Automate versions earlier than 4.13.295 on Linux x86 are susceptible to a condition where an authenticated attacker can access restricted functionality. This is due to improperly neutralized inputs used in an SQL command. The issue allows manipulation of inputs, potentially leading to unauthorized access.
Recommendations Update to version 4.13.295.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13790
CVE-2025-6724

Affected Products

Chef Automate