Northern.tech CFEngine Enterprise
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:*:*:*
- <= 3.26.0
- <= 3.24.2
- <= 3.21.7
A cross-site scripting (XSS) vulnerability has been identified in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. This vulnerability arises from missing input sanitization in the Mission Portal, allowing for the injection of malicious JavaScript that could be executed when an affected user visits a page.
Exploitation of this vulnerability could allow an attacker to inject and execute malicious JavaScript in the context of another user, such as an admin, potentially leading to unauthorized actions or information disclosure.
Users are advised to upgrade to CFEngine Enterprise versions 3.27.0, 3.24.3, or 3.21.8. Instructions for upgrading CFEngine can be found in the CFEngine documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.