Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://northern.tech | vendor advisory |
https://cfengine.com/blog/2022/cve-2021-44215-and-cve-2021-44216/ | exploit vendor advisory |