<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – CFEngine</title>
  <link>https://cvedaily.com/pages/tags/cfengine.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/cfengine.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – CFEngine</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:33 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-33553 – Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-33553</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-33553</guid>
    <pubDate>Tue, 02 Jun 2026 20:16:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-33553</strong></p>
  <p>Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-33553">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24712 – Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24712</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24712</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24712</strong></p>
  <p>Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.</p>
  <p><strong>CVSS:</strong> 7.3 · <strong>CWE:</strong> CWE-77</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24712">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24711 – Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrec...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24711</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24711</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24711</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-284</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24711">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24710 – Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24710</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24710</guid>
    <pubDate>Thu, 14 May 2026 15:16:44 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24710</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24710">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-55958 – Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allow...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55958</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55958</guid>
    <pubDate>Tue, 21 Jan 2025 21:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-55958</strong></p>
  <p>Northern.tech CFEngine Enterprise Mission Portal 3.24.0, 3.21.5, and below allows XSS. The fixed versions are 3.24.1 and 3.21.6.</p>
  <p><strong>CVSS:</strong> 4.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55958">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-45684 – Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-45684</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-45684</guid>
    <pubDate>Tue, 14 Nov 2023 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-45684</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-89</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-45684">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-26560 – Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-26560</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-26560</guid>
    <pubDate>Wed, 26 Apr 2023 00:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-26560</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-203</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-26560">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-44216 – Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Ins...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44216</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44216</guid>
    <pubDate>Thu, 10 Mar 2022 17:44:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-44216</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44216">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-44215 – Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-44215</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-44215</guid>
    <pubDate>Thu, 10 Mar 2022 17:44:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-44215</strong></p>
  <p>Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44215">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-38379 – The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions tha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-38379</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-38379</guid>
    <pubDate>Wed, 27 Oct 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-38379</strong></p>
  <p>The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-38379">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-36756 – CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-36756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-36756</guid>
    <pubDate>Wed, 27 Oct 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-36756</strong></p>
  <p>CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-36756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2019-19394 – Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-19394</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-19394</guid>
    <pubDate>Thu, 16 Apr 2020 19:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2019-19394</strong></p>
  <p>Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-19394">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2019-9929 – Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2019-9929</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2019-9929</guid>
    <pubDate>Thu, 06 Jun 2019 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2019-9929</strong></p>
  <p>Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-532</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2019-9929">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-2960 – cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-2960</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-2960</guid>
    <pubDate>Wed, 05 Oct 2005 19:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-2960</strong></p>
  <p>cfengine 1.6.5 and 2.1.16 allows local users to overwrite arbitrary files via a symlink attack on temporary files used by vicf.in, a different vulnerability than CVE-2005-3137.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-2960">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2005-3137 – The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local user...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2005-3137</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2005-3137</guid>
    <pubDate>Wed, 05 Oct 2005 19:02:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2005-3137</strong></p>
  <p>The (1) cfmailfilter and (2) cfcron.in files for cfengine 1.6.5 allow local users to overwrite arbitrary files via a symlink attack on temporary files, a different vulnerability than CVE-2005-2960.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2005-3137">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2004-1701 – Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1701</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1701</guid>
    <pubDate>Mon, 09 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2004-1701</strong></p>
  <p>Heap-based buffer overflow in the AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 allows remote attackers to execute arbitrary code via a long SAUTH command during RSA authentication.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1701">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2004-1702 – The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 doe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2004-1702</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2004-1702</guid>
    <pubDate>Mon, 09 Aug 2004 04:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2004-1702</strong></p>
  <p>The AuthenticationDialogue function in cfservd for Cfengine 2.0.0 to 2.1.7p1 does not properly check the return value of the ReceiveTransaction function, which leads to a failed malloc call and triggers to a null dereference, which allows remote attackers to cause a denial of service (crash).</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2004-1702">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2003-0849 – Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2003-0849</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2003-0849</guid>
    <pubDate>Mon, 17 Nov 2003 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2003-0849</strong></p>
  <p>Buffer overflow in net.c for cfengine 2.x before 2.0.8 allows remote attackers to execute arbitrary code via certain packets with modified length values, which is trusted by the ReceiveTransaction function when using a buffer provided by the BusyWithConnection function.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2003-0849">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2000-0947 – Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2000-0947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2000-0947</guid>
    <pubDate>Tue, 19 Dec 2000 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2000-0947</strong></p>
  <p>Format string vulnerability in cfd daemon in GNU CFEngine before 1.6.0a11 allows attackers to execute arbitrary commands via format characters in the CAUTH command.</p>
  <p><strong>CVSS:</strong> 10.0 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2000-0947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-1999-0374 – Debian GNU/Linux cfengine package is susceptible to a symlink attack.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-1999-0374</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-1999-0374</guid>
    <pubDate>Tue, 16 Feb 1999 05:00:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-1999-0374</strong></p>
  <p>Debian GNU/Linux cfengine package is susceptible to a symlink attack.</p>
  <p><strong>CVSS:</strong> 2.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-1999-0374">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
