Insecure Permissions in CFEngine Enterprise Allow Unauthorized Access to Log Files

Insecure Permissions in CFEngine Enterprise Allow Unauthorized Access to Log Files

CVE-2021-44216 · MEDIUM Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.

Learn more about our Cis Benchmark Audit For Apache Http Server.