Arbitrary Code Execution Vulnerability in Chef Manage 2.1.0 through 2.4.4

Arbitrary Code Execution Vulnerability in Chef Manage 2.1.0 through 2.4.4

CVE-2017-7174 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

The user-account creation feature in Chef Manage 2.1.0 through 2.4.4 allows remote attackers to execute arbitrary code. This is fixed in 2.4.5.

Learn more about our User Device Pen Test.