Northern.tech CFEngine Enterprise
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:*:*:*
- <= 3.26.0
- <= 3.24.2
- <= 3.21.7
A broken access control vulnerability has been identified in Northern.tech CFEngine Enterprise versions prior to 3.21.8, 3.24.3, and 3.27.0. This vulnerability allows an attacker with a low-privilege user account to access more information than permitted, and in severe cases, escalate privileges to an admin level.
Exploitation of this vulnerability could enable a low-privilege user to bypass access controls, escalate privileges, and gain control over the hub and the entire infrastructure managed by it.
Users are advised to upgrade to CFEngine Enterprise versions 3.27.0, 3.24.3, or 3.21.8. Instructions for upgrading CFEngine can be found in the CFEngine documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.