[CVE-2025-8868] 在 Chef Automate 中炮制 SQL 注入漏洞
xbow.com | 漏洞 | 高危 | CVE-2025-8868 | #vulnerability-research | #devops | #sql-injection | #postgresql | #default-credentials | #chef-automate
摘要
详解 Chef Automate 的 SQL 注入:XBOW 凭鲜为人知的默认 data-collector 令牌取得入口,认证攻击者可对 PostgreSQL 执行任意 SQL,漏洞已上报上游修复。
- CVSS
- 8.8
- 发布时间
- 收录时间
Skip to content