← Back to browse · API

CVE-2025-8868

Severity
CRITICAL
CVSS
9.8
EPSS
0.22827
Risk score
47.19
CISA KEV
No
PoC
No
Published
2025-09-29
Modified
2025-09-29
First seen
2026-08-07
Aliases
EUVD-2025-31570, GHSA-MH28-G8JV-R635
Products
Progress Software:Chef Automate 0 <4.13.295
Sources
euvd EUVD-2025-31570

Description

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

References