Critical severity9.8NVD Advisory· Published Mar 17, 2017· Updated May 13, 2026
CVE-2017-7174
CVE-2017-7174
Description
The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.
Affected products
11cpe:2.3:a:chef_manage_project:chef_manage:2.1.0:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:chef_manage_project:chef_manage:2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.1.2:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.2.0:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:chef_manage_project:chef_manage:2.4.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- discourse.chef.io/t/chef-manage-2-4-5-security-release/10599nvdRelease NotesThird Party Advisory
- www.securityfocus.com/bid/97069nvd
News mentions
0No linked articles in our index yet.