Known Vulnerabilities for Cfengine by Northern.tech
Listed below are 10 of the newest known vulnerabilities associated with "Cfengine" by "Northern.tech".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-33553 json | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-24712 json | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. | Not Provided | 2026-05-14 | 2026-05-15 |
| CVE-2026-24711 json | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. | Not Provided | 2026-05-14 | 2026-05-15 |
| CVE-2026-24710 json | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. | Not Provided | 2026-05-14 | 2026-05-14 |
| CVE-2023-45684 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-14 | 2023-11-20 |
| CVE-2023-26560 json | Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feat... | 6.5 - MEDIUM | 2023-04-26 | 2023-05-08 |
| CVE-2021-44216 json | Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized... | 5.5 - MEDIUM | 2022-03-10 | 2022-03-15 |
| CVE-2021-44215 json | Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to ha... | 5.5 - MEDIUM | 2022-03-10 | 2022-03-15 |
| CVE-2021-38379 json | The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. | 5.5 - MEDIUM | 2021-10-27 | 2021-11-04 |
| CVE-2021-36756 json | CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. | 6.5 - MEDIUM | 2021-10-27 | 2021-11-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Northern.tech | Cfengine | 3.12.2 | |||
| Application | Northern.tech | Cfengine | 3.12.1 |