The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Chef_manage |
Chef |
* |
1.11.4 (including) |
References