Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-28864
HistoryJul 17, 2023 - 12:00 a.m.

CVE-2023-28864

2023-07-1700:00:00
ubuntu.com
ubuntu.com
5
chef infra server
vulnerability
unauthorized access.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

Progress Chef Infra Server before 15.7 allows a local attacker to exploit a
/var/opt/opscode/local-mode-cache/backup world-readable temporary backup
path to access sensitive information, resulting in the disclosure of all
indexed node data, because OpenSearch credentials are exposed. (The data
typically includes credentials for additional systems.) The attacker must
wait for an admin to run the “chef-server-ctl reconfigure” command.

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0

Percentile

5.1%

Related for UB:CVE-2023-28864