CVE-2021-36756: Medium severity gnu cfengine vulnerability
Published Oct 27, 2021
·Updated
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
Affected Software
1 affected component
Northern.tech CFEngine>=3.15.0<=3.15.4
Remediation
Patch Available
Event History
Oct 27, 2021
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
Description
Frequently Asked Questions
1
What is CVE-2021-36756?
CVE-2021-36756 is a vulnerability in CFEngine Enterprise 3.15.0 through 3.15.4 that involves missing SSL certificate validation.
2
What is the severity of CVE-2021-36756?
The severity of CVE-2021-36756 is medium with a severity score of 6.5.
3
How does CVE-2021-36756 affect CFEngine Enterprise?
CVE-2021-36756 affects CFEngine Enterprise 3.15.0 through 3.15.4 by introducing a vulnerability related to missing SSL certificate validation.
4
How can I fix CVE-2021-36756?
To fix CVE-2021-36756, users should update CFEngine Enterprise to version 3.15.5 or later, which addresses the missing SSL certificate validation issue.
5
Is there any additional information available about CVE-2021-36756?
Yes, you can find additional information about CVE-2021-36756 on the CFEngine blog and the CFEngine Enterprise downloads page.