Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
References
Link | Resource |
---|---|
https://cfengine.com/blog/2023/cve-2023-45684/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
20 Nov 2023, 16:36
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | () https://cfengine.com/blog/2023/cve-2023-45684/ - Vendor Advisory | |
CWE | CWE-89 | |
CPE | cpe:2.3:a:northern.tech:cfengine:*:*:*:*:enterprise:*:*:* | |
First Time |
Northern.tech
Northern.tech cfengine |
14 Nov 2023, 15:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-14 15:15
Updated : 2024-02-28 20:54
NVD link : CVE-2023-45684
Mitre link : CVE-2023-45684
CVE.ORG link : CVE-2023-45684
JSON object : View
Products Affected
northern.tech
- cfengine
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')