Vulnerabilities
Vulnerable Software
Northern.tech:  Security Vulnerabilities
The useradm service 1.14.0 (in Northern.tech Mender Enterprise 2.7.x before 2.7.1) and 1.13.0 (in Northern.tech Mender Enterprise 2.6.x before 2.6.1) allows users to access the system with their JWT token after logout, because of missing invalidation (if the JWT verification cache is enabled).
CVSS Score
7.5
EPSS Score
0.002
Published
2021-08-27
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-04-16


Contact Us

Shodan ® - All rights reserved