← Back to CVE List
CVE-2025-8868NVD
Vulnerability Summary
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via
improperly neutralized inputs used in an SQL command using a well-known token.
improperly neutralized inputs used in an SQL command using a well-known token.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Chef Automate < 4.13.295
- Chef Automate >= 20180319150121 and <= 20220329091442
- Chef Automate 4.13.295