# Security Release: Chef Server 12.0.1 and Enterprise Chef 11.2.6

**URL:** https://discourse.chef.io/t/security-release-chef-server-12-0-1-and-enterprise-chef-11-2-6/6080
**Category:** Chef Infra (archive)
**Created:** [December 17, 2014, 10:04pm UTC](https://discourse.chef.io/t/security-release-chef-server-12-0-1-and-enterprise-chef-11-2-6/6080 "2014-12-17T22:04:22Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Mark\_Mzyk\_OLD](https://sea2.discourse-cdn.com/flex016/user_avatar/discourse.chef.io/mark_mzyk_old/32/197_2.png) [@Mark\_Mzyk\_OLD](https://discourse.chef.io/u/Mark_Mzyk_OLD)
#### Post date: [December 17, 2014, 10:04pm UTC](https://discourse.chef.io/t/security-release-chef-server-12-0-1-and-enterprise-chef-11-2-6/6080/1 "2014-12-17T22:04:22Z")

</div>

Hi Chefs,

We just made available a security release of Chef Server 12.0.1 and  
Enterprise Chef Server 11.2.6. This addresses a CSRF vulnerability that was  
found in the doorkeeper gem, which is used by the oc-id service found in  
Chef Server. Open Source Chef Server 11 is not affected by this, as it does  
not ship with the oc-id service.

Full details are in the blog post here:

> **[Security Release: Chef Server 12.0.1 and Enterprise Chef Server 11.2.6 - Chef...](https://blog.chef.io/security-release-chef-server-12-0-1-and-enterprise-chef-server-11-2-6/)**
>
> Available for immediate download are Chef Server 12.0.1 and Enterprise Chef Server 11.2.6. This release addresses CVE-2014-8144, a CSRF vulnerability found in doorkeeper, a gem used by the oc-id service that ships with the Chef Server. This...

Thanks,

Mark Mzyk  
Chef Server Team Engineer
