Incorrect default permissions in cfengine - CVE-2021-44216
Published: May 9, 2023
Vulnerability identifier: #VU75799
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44216
CWE-ID: CWE-276
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to incorrect default permissions for Apache and Mission Portal Application log files. A local user can read the log file and gain access to sensitive information.
Affected software
cfengine
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
Advanced Systems Management Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
cfengine-masterfiles
cfengine
libpromises3-debuginfo
cfengine-debugsource
cfengine-debuginfo
libpromises3
libpromises-devel
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Software Development Kit 12
Advanced Systems Management Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
cfengine-masterfiles
cfengine
libpromises3-debuginfo
cfengine-debugsource
cfengine-debuginfo
libpromises3
libpromises-devel
How to mitigate CVE-2021-44216
Install updates from vendor's website.
cfengine - addressed in versions 3.15.5, 3.18.1
cfengine-masterfiles - update to 3.21.0-10.3.1
cfengine - update to 3.21.0-17.3.1
libpromises3-debuginfo - update to 3.21.0-17.3.1
cfengine-debugsource - update to 3.21.0-17.3.1
cfengine-debuginfo - update to 3.21.0-17.3.1
libpromises3 - update to 3.21.0-17.3.1
libpromises-devel - update to 3.21.0-17.3.1
cfengine-masterfiles - update to 3.21.0-10.3.1
cfengine - update to 3.21.0-17.3.1
libpromises3-debuginfo - update to 3.21.0-17.3.1
cfengine-debugsource - update to 3.21.0-17.3.1
cfengine-debuginfo - update to 3.21.0-17.3.1
libpromises3 - update to 3.21.0-17.3.1
libpromises-devel - update to 3.21.0-17.3.1