Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Northern.tech Subscribe
Filtered by product Cfengine
Total 5 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-44216 1 Northern.tech 1 Cfengine 2022-03-15 2.1 LOW 5.5 MEDIUM
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
CVE-2021-44215 1 Northern.tech 1 Cfengine 2022-03-15 2.1 LOW 5.5 MEDIUM
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
CVE-2021-36756 1 Northern.tech 1 Cfengine 2021-11-04 6.4 MEDIUM 6.5 MEDIUM
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CVE-2021-38379 1 Northern.tech 1 Cfengine 2021-11-04 2.1 LOW 5.5 MEDIUM
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CVE-2019-19394 1 Northern.tech 1 Cfengine 2020-04-22 4.3 MEDIUM 6.1 MEDIUM
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.