CVE-2021-44215 and CVE-2021-44216 - Insecure permissions on log files in CFEngine Enterprise Hub package

"'Nick Anderson' via help-cfengine" <[email protected]>
Newsgroups gmane.comp.sysutils.cfengine.general
Message-ID <[email protected]>
  Hello fellow CFEngineers,

  Please be aware, we have published [CVE-2021-44215] and
  [CVE-2021-44216]. These vulnerabilities relate to permissions of log
  files in the CFEngine Enterprise hub package. If you are already
  running the latest supported versions of CFEngine (3.18.1, 3.15.5) you
  are not affected.

  For more details see our [announcement].


[CVE-2021-44215]
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44215>

[CVE-2021-44216]
<https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-44216>

[announcement]
<http://cfengine.com/blog/2022/cve-2021-44215-and-cve-2021-44216>

-- 
You received this message because you are subscribed to the Google Groups "help-cfengine" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion on the web visit https://groups.google.com/d/msgid/help-cfengine/871qzj54pw.fsf%40northern.tech.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.