CVE Explorer
CVE-2025-6724
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"collectionURL":"https://github.com/chef/automate","defaultStatus":"affected","packageName":"Chef Automate services","platforms":["Linux","64 bit","x86"],"product":"Chef Automate","repo":"https://github.com/chef/automate","vendor":"Progress Software","versions":[{"lessThan":"4.13.295","status":"affected","version":"0","versionType":"Customer on-premises deployed product"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:bf9562ce40c590558de16c8e92f50aef68f41966ac8755bd0f78c591196cc279 · sha256:3b8da44e730f922d… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:bf9562ce40c590558de16c8e92f50aef68f41966ac8755bd0f78c591196cc279 · sha256:3b8da44e730f922d… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-89","description":"CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:bf9562ce40c590558de16c8e92f50aef68f41966ac8755bd0f78c591196cc279 · sha256:3b8da44e730f922d… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://docs.chef.io/release_notes_automate/#4.13.295"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:bf9562ce40c590558de16c8e92f50aef68f41966ac8755bd0f78c591196cc279 · sha256:3b8da44e730f922d… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.