yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-38379
Component Overview
Vulnerability Overview
Name
CVE-2021-38379
Source
NVD (
link
)
Debian (
link
)
Description
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
CWEs
CWE-276
Published Date
Oct 27, 2021
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://cfengine.com/blog/2021/cve-2021-38379-and-cve-2021-36756/
Vendor Advisory
https://docs.cfengine.com/docs/3.18/enterprise-cfengine-guide.html
Vendor Advisory
https://cfengine.com/blog/2021/cve-2021-38379-and-cve-2021-36756/
Vendor Advisory
https://docs.cfengine.com/docs/3.18/enterprise-cfengine-guide.html
Vendor Advisory
Analysis
#
Affected Component
Analysis
cfengine
Exploitable
Vulnerability Ratings
#
5.5
CVSSv31
2.1
CVSSv2
Others affected components
#
Name
Project
Project Version
Version
Status
cfengine
yocto
master
3.26.0
Not Affected
cfengine
yocto
scarthgap
3.21.0
Not Affected