ZeroHour

CVE-2025-8868

moderate

SQL Injection in Progress Chef Automate Compliance Service

CVSS 3.1
8.8 high
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2025-8868 is a SQL injection flaw (CWE-89) in the compliance service of Progress Chef Automate that also results in exposure of sensitive information (CWE-200). An authenticated attacker with low privileges can trigger it remotely without user interaction by sending improperly neutralized input that is used in a SQL command, reportedly via a well-known token. Successful exploitation grants access to restricted compliance-service functionality and can disclose sensitive data, which the high CVSS 3.1 score of 8.8 (C:H/I:H/A:H) reflects. Only Chef Automate versions earlier than 4.13.295 running on the Linux x86 platform are affected. No public proof-of-concept or confirmed in-the-wild exploitation is currently known, but the 24.3% EPSS score (98th percentile) indicates a high probability of exploitation within the next 30 days.

What to do: Upgrade Chef Automate to version 4.13.295 or later on affected Linux x86 installations. Until patched, restrict access to the compliance service to trusted, low-privileged accounts and check whether the well-known token referenced in the advisory is in use, rotating it where feasible. Prioritize patching internet-exposed or multi-tenant Automate instances, given the 98th-percentile EPSS score and the fact that any authenticated user can exploit the flaw.

Affected
Progress (Chef) Chef Automateall versions earlier than 4.13.295 on the Linux x86 platform
Estimated exposure
moderate≈ low thousands of Chef Automate deployments, of which only a minority are internet-exposed (estimate) — Chef Automate is an enterprise-focused, typically on-premises automation and compliance platform with an install base best measured in thousands of deployments, and public internet scans historically show only a small fraction of such…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.

Vendors
chef
Products
automate
Weakness
CWE-89, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.