Security Vulnerability Releases of Chef Server

Blog-L_News_4_1283x494
by | |1 min read

Hello,

Today we are releasing new versions of Enterprise Chef Server and Open Source Chef Server to address a PostgreSQL configuration vulnerability error.

The defect allows any local user on the system hosting the Chef Server’s PostgreSQL components full access to databases.

We advise all Chef Server users to update to this latest release which corrects the error.

This error was discovered and reported by our friends at Gitlab.

Affected versions:

All versions of Enterprise Chef Server 11 are affected. If this impacts you, go here.

All versions of Enterprise Chef Server 1.4 are affected. If this impacts you, go here.

All versions of Open Source Chef Server 11 are affected. If this impacts you, go here.

Please contact us with any questions or concerns.

Joseph Smith

banner background
Ready to Get Started?

Fexible deployment options to suit your enterprise needs—SaaS for a fully managed cloud experience, and Self-Managed for on-premises control.

request a trial

Consult a Progress Expert

Request a consultation with a Progress Professional Services expert.

learn more

All Blogs