The Chef Habitat builder-api on-prem-builder package ...
Moderate severity
Unreviewed
Published
Oct 28, 2024
to the GitHub Advisory Database
•
Updated Oct 28, 2024
Description
Published by the National Vulnerability Database
Oct 28, 2024
Published to the GitHub Advisory Database
Oct 28, 2024
Last updated
Oct 28, 2024
The Chef Habitat builder-api on-prem-builder package with any version lower than habitat/builder-api/10315/20240913162802 is vulnerable to indirect object reference (IDOR) by un-authorized deletion of personal token. Habitat builder consumes builder-api habitat package as a dependency and the vulnerability was specifically due to builder-api habitat package.
The fix was made available in habitat/builder-api/10315/20240913162802 and all the subsequent versions after that. We would recommend user to always use on-prem stable channel.
References