Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
References
Link Resource
https://cfengine.com/blog/2023/cve-2023-45684/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-11-14T00:00:00

Updated: 2023-11-14T14:45:21.677019

Reserved: 2023-10-10T00:00:00


Link: CVE-2023-45684

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-14T15:15:07.553

Modified: 2023-11-20T16:36:42.880


Link: CVE-2023-45684

JSON object: View

cve-icon Redhat Information

No data.

CWE