Please patch CVEs for package cfengine version 3.15.3 INFO (CVEs are): cfengine 3.15.3 cves found CVE-2021-36756 Desc: CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation. Link: https://nvd.nist.gov/vuln/detail/CVE-2021-36756 Severity: MEDIUM CVE-2021-38379 Desc: The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure. Link: https://nvd.nist.gov/vuln/detail/CVE-2021-38379 Severity: MEDIUM CVE-2021-44215 Desc: Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact. Link: https://nvd.nist.gov/vuln/detail/CVE-2021-44215 Severity: MEDIUM CVE-2021-44216 Desc: Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files. Link: https://nvd.nist.gov/vuln/detail/CVE-2021-44216 Severity: MEDIUM CVE-2023-26560 Desc: Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials. Link: https://nvd.nist.gov/vuln/detail/CVE-2023-26560 Severity: MEDIUM
*** Bug 13827 has been marked as a duplicate of this bug. ***
Предлагаю закрыть уязвимости обновлением, прямых патчей нет. Незнаю для чего нам эта программа в main. cfengine 3.21.3-1 https://abf.io/build_lists/4828748 https://abf.io/build_lists/4828749 https://abf.io/build_lists/4828750 https://abf.io/build_lists/4828751 https://abf.io/build_lists/4828752
Тоже не нашел, для чего она в main
(In reply to Aleksandr Proklov from comment #2) > Предлагаю закрыть уязвимости обновлением, прямых патчей нет. > Незнаю для чего нам эта программа в main. > > cfengine 3.21.3-1 > > https://abf.io/build_lists/4828748 > https://abf.io/build_lists/4828749 > https://abf.io/build_lists/4828750 > https://abf.io/build_lists/4828751 The update sent to testings ------------------------------------ > https://abf.io/build_lists/4828752 не опубликовано ошибка сборки
cfengine-3.21.3-1 https://abf.io/build_lists/4828748 https://abf.io/build_lists/4828749 https://abf.io/build_lists/4828750 https://abf.io/build_lists/4828751 https://abf.io/build_lists/4828752 ************************ Advisory ************************* CVEs closed by version update *********************************************************** QA Verified
******************************************************* Secteam_verified ******************************************************* https://abf.rosalinux.ru/advisories/ROSA-SA-2024-2436 *******************************************************