VYPR

Cfengine

by Northern.tech

CVEs (13)

  • CVE-2023-45684HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.

  • CVE-2026-24712HigMay 14, 2026
    risk 0.48cvss 7.3epss 0.01

    Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

  • CVE-2023-26560MedApr 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.

  • CVE-2021-36756MedOct 27, 2021
    risk 0.42cvss 6.5epss 0.00

    CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.

  • CVE-2026-24710MedMay 14, 2026
    risk 0.40cvss 6.1epss 0.00

    Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.

  • CVE-2019-19394MedApr 16, 2020
    risk 0.40cvss 6.1epss 0.01

    Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.

  • CVE-2021-44216MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.

  • CVE-2021-44215MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.

  • CVE-2021-38379MedOct 27, 2021
    risk 0.36cvss 5.5epss 0.00

    The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.

  • CVE-2026-24711MedMay 14, 2026
    risk 0.34cvss 5.3epss 0.00

    Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.

  • CVE-2024-55958MedJan 21, 2025
    risk 0.31cvss 4.8epss 0.00

    Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.

  • CVE-2003-0849Nov 17, 2003
    risk 0.04cvss epss 0.11

    Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.

  • CVE-2005-3137Oct 5, 2005
    risk 0.00cvss epss 0.00

    The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.