Northern.tech CFEngine Enterprise
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:*:*:*
- 3.24.3
- 3.27.0
A cross-site scripting (XSS) vulnerability has been identified in Northern.tech CFEngine Enterprise versions 3.24.3 prior to 3.24.4 and 3.27.0 prior to 3.27.1. The issue arises in the Mission Portal due to an incorrect content-type HTTP header in some API endpoints. This flaw allows low-privilege users to inject malicious JavaScript that could be executed by an admin user, potentially leading to unauthorized privilege escalation.
Exploitation of this vulnerability could allow an authenticated low-privilege user to execute malicious JavaScript in the context of an admin user, potentially escalating their privileges and gaining control over the hub and its managed infrastructure.
Users are advised to upgrade to CFEngine Enterprise versions 3.24.4, 3.27.1, or later. For upgrade instructions, please refer to the CFEngine documentation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.