CVE Vulnerabilities

CVE-2023-26560

Published: Apr 26, 2023 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.

Affected Software

Name Vendor Start Version End Version
Cfengine Northern.tech 3.6.0 (including) 3.21.1 (excluding)

References