yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-36756
Component Overview
Vulnerability Overview
Name
CVE-2021-36756
Source
NVD (
link
)
Debian (
link
)
Description
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
CWEs
CWE-295
Published Date
Oct 27, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://cfengine.com/blog/2021/cve-2021-38379-and-cve-2021-36756/
Patch
https://cfengine.com/downloads/cfengine-enterprise/
Patch
https://cfengine.com/blog/2021/cve-2021-38379-and-cve-2021-36756/
Patch
https://cfengine.com/downloads/cfengine-enterprise/
Patch
Analysis
#
Affected Component
Analysis
cfengine
Exploitable
Vulnerability Ratings
#
6.5
CVSSv31
6.4
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
cfengine
yocto
master
3.26.0
Not Affected
cfengine
yocto
scarthgap
3.21.0
Not Affected