Checkmk

Checkmk

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.49%
  • Veröffentlicht 20.02.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 07:33:09

No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.

  • EPSS 0.22%
  • Veröffentlicht 20.02.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 07:33:09

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log...

  • EPSS 0.23%
  • Veröffentlicht 20.02.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 07:33:09

Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.

Exploit
  • EPSS 0.28%
  • Veröffentlicht 20.02.2023 17:15:12
  • Zuletzt bearbeitet 21.11.2024 07:33:09

Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.

  • EPSS 0.23%
  • Veröffentlicht 09.02.2023 09:15:11
  • Zuletzt bearbeitet 21.11.2024 07:26:29

Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows the site user to escalate privileges via a manipulated unixcat executable

  • EPSS 0.92%
  • Veröffentlicht 26.01.2023 21:18:07
  • Zuletzt bearbeitet 21.11.2024 07:36:53

Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.

  • EPSS 0.49%
  • Veröffentlicht 09.01.2023 17:15:11
  • Zuletzt bearbeitet 21.11.2024 07:36:08

Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.

  • EPSS 0.2%
  • Veröffentlicht 17.06.2022 13:15:16
  • Zuletzt bearbeitet 21.11.2024 07:08:35

A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected. Using the shipped version of the agents, the maintainer scripts locat...

  • EPSS 0.39%
  • Veröffentlicht 20.05.2022 23:15:45
  • Zuletzt bearbeitet 21.11.2024 07:04:14

In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

Exploit
  • EPSS 3.76%
  • Veröffentlicht 25.03.2022 23:15:08
  • Zuletzt bearbeitet 21.11.2024 06:25:04

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitat...