Chef Security Releases: 11.12.8 & 10.32.2-2

Blog-Icon_7_100x385
by | |1 min read

Ohai Chefs,

Today we are releasing Chef Client 11.12.8 & 10.32.2-2 which include an updated version of OpenSSL that patches CVE-2014-0224. All installs of Chef Client should be upgraded immediately. This bug permits an attacker to execute an undetectable MITM attack on an otherwise secure connection. As a result, the attacker could read or alter any traffic between the client and the server. This would include secret data such as usernames, passwords, node data, data bags, etc. The severity of this exploit cannot be overstated. Please follow the upgrade instructions below carefully to ensure that your Chef Client install is fully patched.

For information about the windows packages that contain the fix for this vulnerability please check out this.

Upgrade Instructions

As usual you can get these releases with our install script:

curl -L https://www.opscode.com/chef/install.sh | sudo bash -s -- -v 10.32.2 
curl -L https://www.opscode.com/chef/install.sh | sudo bash -s -- -v 11.12.8

Extra Precautions

As an extra precaution, you may want to change any secrets (such as usernames, passwords, encrypted data bags) that may have been sent between the client and the server. If an attacker was executing this attack he/she would be able to see this data in “plain-text”. Please reach out to us if you are having any troubles with these releases.

banner background
Ready to Get Started?

Fexible deployment options to suit your enterprise needs—SaaS for a fully managed cloud experience, and Self-Managed for on-premises control.

request a trial

Consult a Progress Expert

Request a consultation with a Progress Professional Services expert.

learn more

All Blogs

Related Tags