CVE-2019-19394: XSS
Published Apr 16, 2020
·Updated
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
Affected Software
3 affected components
Northern.tech CFEngine>=3.10.0<3.10.7
Northern.tech CFEngine>=3.12.0<3.12.3
Northern.tech CFEngine=3.7
Event History
Apr 16, 2020
CVE Published
via MITRE·05:48 PM
Data Sourced
via MITRE·05:48 PM
Description
Frequently Asked Questions
1
What is CVE-2019-19394?
CVE-2019-19394 is a vulnerability in Northern.tech CFEngine Enterprise that allows XSS (cross-site scripting).
2
What is the severity level of CVE-2019-19394?
The severity level of CVE-2019-19394 is medium with a score of 6.1.
3
Which versions of Northern.tech CFEngine Enterprise are affected by CVE-2019-19394?
Versions 3.10.0 to 3.10.7, 3.12.0 to 3.12.3, and 3.7 are affected by CVE-2019-19394.
4
How can I fix CVE-2019-19394?
To fix CVE-2019-19394, update Northern.tech CFEngine Enterprise to version 3.10.7, 3.12.3, or 3.15.0.
5
Where can I find more information about CVE-2019-19394?
More information about CVE-2019-19394 can be found at this link: https://cfengine.com/company/blog-detail/cve-2019-19394-mission-portal-javascript-injection-vulnerability/