CVE-2023-45684
CFEngine vulnerability analysis and mitigation

Overview

Northern.tech CFEngine Enterprise before version 3.21.3 contains a SQL injection vulnerability in the Mission Portal login page. The vulnerability was discovered in version 3.6.0 and affects all versions up to 3.21.3. Fixed versions are 3.18.6 and 3.21.3 (NVD).

Technical details

The vulnerability exists in the Mission Portal login page of the CFEngine hub. It has been assigned a CVSS v3.1 base score of 7.5 (HIGH) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N. The vulnerability is classified as CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection'). While the queried results are not directly visible in the server's response to the API request, attackers can craft special queries using logical conditions combined with PG_SLEEP function to perform time-based blind SQL injection attacks (Vendor Advisory).

Impact

The vulnerability allows attackers to extract the contents of the entire underlying database through time-based blind SQL injection techniques. This includes access to sensitive information such as access tokens and salted password hashes stored in the database (Vendor Advisory).

Mitigation and workarounds

Users are strongly recommended to upgrade to CFEngine Enterprise versions 3.18.6 or 3.21.3, which contain the necessary security fixes. The vulnerability only affects the CFEngine hub, so installing the updated hub package is sufficient for remediation (Vendor Advisory).

Additional resources


SourceThis report was generated using AI

Related CFEngine vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-45684HIGH7.5
  • CFEngineCFEngine
  • cfengine
NoYesNov 14, 2023
CVE-2023-26560MEDIUM6.5
  • CFEngineCFEngine
  • cfengine
NoYesApr 26, 2023
CVE-2021-44216MEDIUM5.5
  • CFEngineCFEngine
  • libpromises3
NoYesMar 10, 2022
CVE-2021-44215MEDIUM5.5
  • CFEngineCFEngine
  • cfengine
NoYesMar 10, 2022
CVE-2021-38379MEDIUM5.5
  • CFEngineCFEngine
  • cfengine
NoNoOct 27, 2021

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management