yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-45684
Component Overview
Vulnerability Overview
Name
CVE-2023-45684
Source
NVD (
link
)
Debian (
link
)
Description
Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.
CWEs
CWE-89
Published Date
Nov 14, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://cfengine.com/blog/2023/cve-2023-45684/
Vendor Advisory
https://cfengine.com/blog/2023/cve-2023-45684/
Vendor Advisory
Analysis
#
Affected Component
Analysis
cfengine
Exploitable
Vulnerability Ratings
#
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
cfengine
yocto
master
3.26.0
Not Affected
cfengine
yocto
scarthgap
3.21.0
Exploitable