CVE-2021-38379: Medium severity gnu cfengine vulnerability
Published Oct 27, 2021
·Updated
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
Affected Software
1 affected component
Northern.tech CFEngine>=3.6.7<=3.18.0
Event History
Oct 27, 2021
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Frequently Asked Questions
1
What is CVE-2021-38379?
CVE-2021-38379 is a vulnerability in the Hub component of CFEngine Enterprise 3.6.7 through 3.18.0 that allows local information disclosure due to insecure permissions.
2
What is the severity of CVE-2021-38379?
The severity of CVE-2021-38379 is medium with a CVSS 3.1 base score of 5.5.
3
How does CVE-2021-38379 impact CFEngine Enterprise?
CVE-2021-38379 allows local attackers to gain unauthorized access to sensitive information stored in the Hub component of CFEngine Enterprise.
4
What is the affected software version range for CVE-2021-38379?
CVE-2021-38379 affects CFEngine Enterprise versions 3.6.7 through 3.18.0.
5
Is there a fix available for CVE-2021-38379?
Yes, it is recommended to update CFEngine Enterprise to a version that is not affected by CVE-2021-38379.