Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://northern.tech | vendor advisory |
https://cfengine.com/blog/2022/cve-2021-44215-and-cve-2021-44216/ | vendor advisory exploit |