漏洞描述 Progress Chef Automate 是一款用于自动化基础设施和应用程序管理的工具。该漏洞存在于 /api/v0/compliance/profiles/search 接口中,攻击者可以通过构造恶意的 SQL 查询注入数据,绕过身份验证并获取敏感信息,可能导致数据泄露和系统完整性破坏。
相关漏洞推荐 (CVE-2025-8868)Chef Automate SQL注入漏洞 Progress Telerik Report Server /Startup/Register 未授权访问漏洞(CVE-2024-4358) POC CVE-2024-1212: Progress Kemp LoadMaster - Command Injection POC CVE-2024-2389: Progress Kemp Flowmon - Command Injection POC CVE-2024-4358: Progress Telerik Report Server - Authentication Bypass POC CVE-2024-4885: Progress Software WhatsUp Gold GetFileWithoutZip Directory Traversal - Remote Code Execution POC rds-automated-backup-disabled: RDS Automated Backups - Disabled POC rds-backup-enable: RDS Automated Backup Check POC CVE-2024-2389: Progress Flowmon rce POC azure-appservice-backup-not-enabled: Azure App Service Automated Backup Not Configured POC gcloud-sql-backups-disabled: Automated Backups Not Enabled for Cloud SQL Instances POC CVE-2025-8868: Chef Automate < 4.13.295 — SQL Injection Microsoft Power Automate 信息泄露漏洞