Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
| Software | From | Fixed in |
|---|---|---|
| northern.tech / cfengine | 3.10.0 | 3.10.7 |
| northern.tech / cfengine | 3.7 | 3.7.x |
| northern.tech / cfengine | 3.12.0 | 3.12.3 |