Description
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-49973 | Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub. |
References
| Link | Providers |
|---|---|
| https://cfengine.com/blog/2023/cve-2023-45684/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-03T15:13:52.177Z
Reserved: 2023-10-10T00:00:00.000Z
Link: CVE-2023-45684
Updated: 2024-08-02T20:29:31.177Z
Status : Modified
Published: 2023-11-14T15:15:07.553
Modified: 2024-11-21T08:27:12.860
Link: CVE-2023-45684
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD