Impact
This flaw, representing a CWE-306 authentication bypass, occurs in the Chef Automate API gateway and identity validation path, allowing an unauthenticated actor to gain elevated access to protected functionality under specific conditions. The vulnerability enables bypassing authentication controls, allowing the attacker to execute privileged operations that could compromise system integrity, confidentiality, and availability.
Affected Systems
Progress Software Chef Automate versions 4.13.516 through 4.13.519 are affected. Versions prior to 4.13.516 are not affected, and upgrades to 4.13.520 or later contain the fix.
Risk and Exploitability
The CVSS score of 10 signals critical vulnerability. No EPSS data is available, and the issue is not listed in CISA KEV, indicating no known active exploitation campaigns. The likely attack vector would be via the specific conditions required for the breach, which are not detailed in the description.
OpenCVE Enrichment