Описание
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
Ссылки
- MitigationVendor Advisory
- Product
- MitigationVendor Advisory
- Product
Уязвимые конфигурации
Конфигурация 1Версия от 3.6.0 (включая) до 3.21.1 (исключая)
cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:*
EPSS
Процентиль: 55%
0.00326
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-203
Связанные уязвимости
CVSS3: 6.5
github
почти 3 года назад
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
EPSS
Процентиль: 55%
0.00326
Низкий
6.5 Medium
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-203