CVE-2024-55958
- EPSS 0.18%
- Veröffentlicht 21.01.2025 21:15:11
- Zuletzt bearbeitet 22.01.2025 22:15:09
Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.
CVE-2023-45684
- EPSS 0.58%
- Veröffentlicht 14.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:27:12
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
CVE-2023-26560
- EPSS 0.35%
- Veröffentlicht 26.04.2023 00:15:09
- Zuletzt bearbeitet 04.02.2025 16:15:35
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
CVE-2021-44216
- EPSS 0.06%
- Veröffentlicht 10.03.2022 17:44:14
- Zuletzt bearbeitet 21.11.2024 06:30:36
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
CVE-2021-44215
- EPSS 0.06%
- Veröffentlicht 10.03.2022 17:44:13
- Zuletzt bearbeitet 21.11.2024 06:30:35
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
CVE-2021-38379
- EPSS 0.03%
- Veröffentlicht 27.10.2021 15:15:08
- Zuletzt bearbeitet 21.11.2024 06:16:56
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CVE-2021-36756
- EPSS 0.09%
- Veröffentlicht 27.10.2021 15:15:07
- Zuletzt bearbeitet 21.11.2024 06:14:01
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CVE-2019-19394
- EPSS 0.36%
- Veröffentlicht 16.04.2020 19:15:22
- Zuletzt bearbeitet 21.11.2024 04:34:42
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.