Vulnerabilities > Northern Tech > Cfengine > 3.12.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-11-14 | CVE-2023-45684 | SQL Injection vulnerability in Northern.Tech Cfengine Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. | 7.5 |
2023-04-26 | CVE-2023-26560 | Unspecified vulnerability in Northern.Tech Cfengine Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials. | 6.5 |
2022-03-10 | CVE-2021-44215 | Incorrect Default Permissions vulnerability in Northern.Tech Cfengine Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. | 5.5 |
2022-03-10 | CVE-2021-44216 | Incorrect Default Permissions vulnerability in Northern.Tech Cfengine Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files. | 5.5 |
2021-10-27 | CVE-2021-38379 | Incorrect Default Permissions vulnerability in Northern.Tech Cfengine The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. | 5.5 |
2020-04-16 | CVE-2019-19394 | Cross-site Scripting vulnerability in Northern.Tech Cfengine 3.12.1/3.12.2/3.7 Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. | 6.1 |