VYPR
Unrated severityNVD Advisory· Published Aug 8, 2012· Updated Apr 29, 2026

CVE-2011-5097

CVE-2011-5097

Description

chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.

Affected products

22
  • Opscode/Chef22 versions
    cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*+ 21 more
    • cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*range: <=0.9.16
    • cpe:2.3:a:opscode:chef:0.10.0:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.10:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.12:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.14:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.2:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.6:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.7.8:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.8.10:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.8.2:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.8.4:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.8.6:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.8.8:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.0:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.10:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.12:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.14:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.2:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.4:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.6:*:*:*:*:*:*:*
    • cpe:2.3:a:opscode:chef:0.9.8:*:*:*:*:*:*:*

Patches

1

Vulnerability mechanics

Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.

References

2

News mentions

0

No linked articles in our index yet.