The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.openwall.com/lists/oss-security/2015/12/14/14 | third party advisory mailing list |
https://github.com/chef/chef/issues/3871 | third party advisory patch |
https://discourse.chef.io/t/chef-infra-client-15-4-45-released/16081 | |
https://github.com/chef/chef/pull/8885 |