The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://docs.cfengine.com/docs/3.18/enterprise-cfengine-guide.html | vendor advisory |
https://cfengine.com/blog/2021/cve-2021-38379-and-cve-2021-36756/ | vendor advisory |