Vulnerabilities > Northern Tech > Cfengine > 3.12.1

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-45684 SQL Injection vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection.
network
low complexity
northern-tech CWE-89
7.5
2023-04-26 CVE-2023-26560 Unspecified vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
network
low complexity
northern-tech
6.5
2022-03-10 CVE-2021-44215 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
local
low complexity
northern-tech CWE-276
2.1
2022-03-10 CVE-2021-44216 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
local
low complexity
northern-tech CWE-276
2.1
2021-10-27 CVE-2021-38379 Incorrect Default Permissions vulnerability in Northern.Tech Cfengine
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
local
low complexity
northern-tech CWE-276
2.1
2020-04-16 CVE-2019-19394 Cross-site Scripting vulnerability in Northern.Tech Cfengine 3.12.1/3.12.2/3.7
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS.
4.3