Vulnerabilities > Northern Tech

DATE CVE VULNERABILITY TITLE RISK
2021-08-27 CVE-2021-35342 Insufficient Session Expiration vulnerability in Northern.Tech Useradm 1.13.0/1.14.0
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
network
low complexity
northern-tech CWE-613
7.5
2020-04-16 CVE-2019-19394 Cross-site Scripting vulnerability in Northern.Tech Cfengine 3.12.1/3.12.2/3.7
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS.
network
low complexity
northern-tech CWE-79
6.1