Northern.tech CFEngine Enterprise
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:*:*:*
- <= 3.26.0
- <= 3.24.2
- <= 3.21.7
A command injection vulnerability has been identified in Northern.tech CFEngine Enterprise and Community versions prior to 3.21.8, 3.24.3, and 3.27.0. This vulnerability arises from missing input sanitization in the CFEngine policy language, allowing injected shell commands to be executed inappropriately, particularly when custom policies process external data.
Exploitation of this vulnerability could enable an attacker to inject and execute arbitrary shell commands on the hub, especially through custom policies that manage users or similar resources.
Users are advised to upgrade to CFEngine version 3.27.0, 3.24.3, 3.21.8, or later. Instructions for upgrading CFEngine are available in the CFEngine documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.