The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.Referenceshttp://www.kb.cert.org/vuls/id/586503