Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Hardcoded credentials in embedded content
Vulnerability Description
A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers. The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating this access method entirely.
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:H/SI:N/SA:L/E:P/S:N/AU:Y/RE:L
Vulnerability Type
凭证传输未经安全保护
Vulnerability Title
Progress Chef Chef360 加密问题漏洞
Vulnerability Description
Progress Chef Chef360是Progress Chef组织的一款基础设施自动化配置与合规管理平台。 Progress Chef Chef360 1.7.1之前版本存在加密问题漏洞,该漏洞源于嵌入静态凭据,可能导致未经身份验证的攻击者访问内部消息队列。
CVSS Information
N/A
Vulnerability Type
N/A