CVE-2025-8868
moderateSQL Injection in Progress Chef Automate Compliance Service
CVE-2025-8868 is a SQL injection flaw (CWE-89) in the compliance service of Progress Chef Automate that also results in exposure of sensitive information (CWE-200). An authenticated attacker with low privileges can trigger it remotely without user interaction by sending improperly neutralized input that is used in a SQL command, reportedly via a well-known token. Successful exploitation grants access to restricted compliance-service functionality and can disclose sensitive data, which the high CVSS 3.1 score of 8.8 (C:H/I:H/A:H) reflects. Only Chef Automate versions earlier than 4.13.295 running on the Linux x86 platform are affected. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, but the 24.3% EPSS score (98th percentile) indicates a high probability of exploitation within the next 30 days.
What to do: Upgrade Chef Automate to version 4.13.295 or later on affected Linux x86 installations. Until patched, restrict access to the compliance service to trusted, low-privileged accounts and check whether the well-known token referenced in the advisory is in use, rotating it where feasible. Prioritize patching internet-exposed or multi-tenant Automate instances, given the 98th-percentile EPSS score and the fact that any authenticated user can exploit the flaw.
| Progress (Chef) Chef Automate | all versions earlier than 4.13.295 on the Linux x86 platform |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
- Vendors
- chef
- Products
- automate
- Weakness
- CWE-89, CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.