Unrated severityNVD Advisory· Published Aug 8, 2012· Updated Apr 29, 2026
CVE-2011-5097
CVE-2011-5097
Description
chef-server-api/app/controllers/cookbooks.rb in Chef Server in Chef before 0.9.18, and 0.10.x before 0.10.2, does not require administrative privileges for the update and destroy methods, which allows remote authenticated users to (1) upload cookbooks via a knife cookbook upload command or (2) delete cookbooks via a knife cookbook delete command.
Affected products
22cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*+ 21 more
- cpe:2.3:a:opscode:chef:*:*:*:*:*:*:*:*range: <=0.9.16
- cpe:2.3:a:opscode:chef:0.10.0:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.10:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.12:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.14:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.2:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.4:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.6:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.7.8:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.8.10:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.8.4:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.8.6:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.8.8:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.0:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.10:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.12:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.14:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.2:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.4:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.6:*:*:*:*:*:*:*
- cpe:2.3:a:opscode:chef:0.9.8:*:*:*:*:*:*:*
Patches
1a4ea6edab2fehttps://github.com/opscode/chefvia nvd-ref
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
2News mentions
0No linked articles in our index yet.