← Back

CVE-2025-6724

nvd nist
Published: Sep 29, 2025Modified: Oct 16, 2025

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: security@progress.com (Secondary)

Description

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.

Affected (2)

Products: Chef: Automate
1 product
Automate
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Chef
Before 4.13.295
From 20180319150121 to 20220329091442
Running on/withPlatform Versions
Linux
Linux Kernel
All versions

References (1)

Timeline

No history available yet.