PT-2021-22093 · Cfengine · Cfengine Enterprise

Vratislav Podzimek

·

Published

2021-10-27

·

Updated

2024-06-27

·

CVE-2021-38379

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions CFEngine Enterprise versions 3.6.7 through 3.18.0
Description The issue concerns Insecure Permissions in The Hub component, which can lead to local Information Disclosure.
Recommendations For versions 3.6.7 through 3.18.0, update to a version that addresses the Insecure Permissions issue to prevent local Information Disclosure.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-38379
OPENSUSE-SU-2024:11873-1
ROSA-SA-2024-2436

Affected Products

Cfengine Enterprise