Checkmk

Checkmk

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 07.04.2026 12:08:50
  • Zuletzt bearbeitet 22.04.2026 13:16:20

Insufficient sanitization of dashboard dashlet title links in Checkmk 2.2.0 (EOL), Checkmk 2.3.0 before 2.3.0p46, Checkmk 2.4.0 before 2.4.0p25, and Checkmk 2.5.0 (beta) before 2.5.0 allows an attacker with dashboard creation privileges to perform st...

  • EPSS 0.24%
  • Veröffentlicht 01.04.2026 10:07:21
  • Zuletzt bearbeitet 07.04.2026 20:51:23

Insufficient permission validation on multiple REST API Quick Setup endpoints in Checkmk 2.5.0 (beta) before version 2.5.0b2 and 2.4.0 before version 2.4.0p25 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • EPSS 0.15%
  • Veröffentlicht 31.03.2026 13:51:02
  • Zuletzt bearbeitet 02.04.2026 12:06:00

Stored cross-site scripting (XSS) in Checkmk version 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create pending changes to inject malicious JavaScript into the Pending Changes sidebar, which will execute in the browsers ...

  • EPSS 0.14%
  • Veröffentlicht 31.03.2026 13:44:17
  • Zuletzt bearbeitet 02.04.2026 12:05:12

Stored cross-site scripting (XSS) in Checkmk 2.5.0 (beta) before 2.5.0b2 allows authenticated users with permission to create hosts or services to execute arbitrary JavaScript in the browsers of other users performing searches in the Unified Search f...

  • EPSS 0.33%
  • Veröffentlicht 24.03.2026 11:25:58
  • Zuletzt bearbeitet 12.05.2026 13:34:29

Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.

  • EPSS 0.19%
  • Veröffentlicht 13.03.2026 09:40:43
  • Zuletzt bearbeitet 18.03.2026 13:23:32

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows unauthenticated users to enumerate existing hosts by observing different HTTP response codes in deploy_agent endpoint, which coul...

  • EPSS 0.24%
  • Veröffentlicht 13.03.2026 09:40:05
  • Zuletzt bearbeitet 18.03.2026 13:37:29

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p23, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows authenticated users to enumerate existing hosts by observing different HTTP response codes in agent-receiver/register_existing en...

  • EPSS 0.17%
  • Veröffentlicht 04.03.2026 13:15:41
  • Zuletzt bearbeitet 05.03.2026 18:39:15

A logic error in the remove_password() function in Checkmk GmbH's Checkmk versions <2.4.0p23, <2.3.0p43, and 2.2.0 (EOL) allows a low-privileged user to cause data loss.

Medienbericht
  • EPSS 0.14%
  • Veröffentlicht 26.02.2026 10:26:00
  • Zuletzt bearbeitet 05.03.2026 15:16:10

Improper neutralization of input in Checkmk versions 2.4.0 before 2.4.0p22, and 2.3.0 before 2.3.0p43 allows an attacker that can manipulate a host's check output to inject malicious JavaScript into the Synthetic Monitoring HTML logs, which can then ...

  • EPSS 0.23%
  • Veröffentlicht 09.02.2026 15:29:16
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Improper permission enforcement in Checkmk versions 2.4.0 before 2.4.0p21, 2.3.0 before 2.3.0p43, and 2.2.0 (EOL) allows users with the "Use WATO" permission to access the "Analyze configuration" page by directly navigating to its URL, bypassing the ...