First published: Wed Oct 27 2021(Updated: )
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
GNU CFEngine | >=3.6.7<=3.18.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-38379 is a vulnerability in the Hub component of CFEngine Enterprise 3.6.7 through 3.18.0 that allows local information disclosure due to insecure permissions.
The severity of CVE-2021-38379 is medium with a CVSS 3.1 base score of 5.5.
CVE-2021-38379 allows local attackers to gain unauthorized access to sensitive information stored in the Hub component of CFEngine Enterprise.
CVE-2021-38379 affects CFEngine Enterprise versions 3.6.7 through 3.18.0.
Yes, it is recommended to update CFEngine Enterprise to a version that is not affected by CVE-2021-38379.