CVE-2023-45684: Northern.tech Cfengine

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

Northern.tech CFEngine Enterprise before 3.21.3 allows SQL Injection. The fixed versions are 3.18.6 and 3.21.3. The earliest affected version is 3.6.0. The issue is in the Mission Portal login page in the CFEngine hub.

Affected products

  • Northern.tech Cfengine: before 3.18.6 (fixed in 3.18.6); from 3.19.0, before 3.21.3 (fixed in 3.21.3)

Published 2023-11-14. Last modified 2026-06-17.