CyberRota Analysis
This is a critical severity vulnerability with a CVSS score of 9.8. It affects Linux. Its EPSS score suggests a 22.8% probability of exploitation in the next 30 days. Exploitation may require the attacker to be authenticated.
CVE
CVE-2025-8868
Severity
CRITICAL
CVSS
9.8
EPSS
22.83%
Linux
Original NVD Description
In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token.
Related CVEs
Other vulnerabilities affecting the same vendor(s)