In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
References
Link | Resource |
---|---|
https://docs.chef.io/release_notes_automate/#4.13.295 | Patch |
Configurations
Configuration 1 (hide)
AND |
|
History
16 Oct 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:a:chef:automate:*:*:*:*:*:*:*:* |
|
References | () https://docs.chef.io/release_notes_automate/#4.13.295 - Patch | |
First Time |
Linux
Chef automate Linux linux Kernel Chef |
29 Sep 2025, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-29 12:15
Updated : 2025-10-16 17:15
NVD link : CVE-2025-6724
Mitre link : CVE-2025-6724
CVE.ORG link : CVE-2025-6724
JSON object : View
Products Affected
linux
- linux_kernel
chef
- automate
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')