GHSA-mh28-g8jv-r635
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via
improperly neutralized inputs used in an SQL command using a well-known token.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: November 23, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.