Vulnerabilities (CVE)

Filtered by vendor Northern.tech Subscribe
Filtered by product Cfengine
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-36756 1 Northern.tech 1 Cfengine 2021-11-04 6.4 MEDIUM 6.5 MEDIUM
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CVE-2021-38379 1 Northern.tech 1 Cfengine 2021-11-04 2.1 LOW 5.5 MEDIUM
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CVE-2019-19394 1 Northern.tech 1 Cfengine 2020-04-22 4.3 MEDIUM 6.1 MEDIUM
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.