Checkmk

Checkmk

109 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.18%
  • Veröffentlicht 18.12.2025 14:15:59
  • Zuletzt bearbeitet 23.12.2025 17:04:50

SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts ...

  • EPSS 0.21%
  • Veröffentlicht 18.12.2025 09:11:17
  • Zuletzt bearbeitet 23.12.2025 17:03:40

Insufficient permission validation in Checkmk versions prior to 2.4.0p17 and 2.3.0p42 allow low-privileged users to view agent information via the REST API, which could lead to information disclosure.

  • EPSS 0.17%
  • Veröffentlicht 18.11.2025 15:11:35
  • Zuletzt bearbeitet 24.11.2025 14:27:29

Insufficient permission validation on multiple REST API endpoints in Checkmk 2.2.0, 2.3.0, and 2.4.0 before version 2.4.0p16 allows low-privileged users to perform unauthorized actions or obtain sensitive information

  • EPSS 0.14%
  • Veröffentlicht 18.11.2025 15:11:17
  • Zuletzt bearbeitet 24.11.2025 13:58:28

Insufficient permission validation in Checkmk 2.4.0 before version 2.4.0p16 allows low-privileged users to modify notification parameters via the REST API, which could lead to unauthorized actions or information disclosure.

  • EPSS 0.09%
  • Veröffentlicht 18.11.2025 15:10:53
  • Zuletzt bearbeitet 24.11.2025 14:13:26

In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially le...

Medienbericht Exploit
  • EPSS 0.56%
  • Veröffentlicht 30.10.2025 10:43:08
  • Zuletzt bearbeitet 03.12.2025 20:06:16

Cross-Site Scripting (XSS) vulnerability in Checkmk's distributed monitoring allows a compromised remote site to inject malicious HTML code into service outputs in the central site. Affecting Checkmk before 2.4.0p14, 2.3.0p39, 2.2.0 and 2.1.0 (eol).

Medienbericht Exploit
  • EPSS 0.63%
  • Veröffentlicht 09.10.2025 15:01:55
  • Zuletzt bearbeitet 04.12.2025 20:37:25

Insufficient escaping in the report scheduler within Checkmk <2.4.0p13, <2.3.0p38, <2.2.0p46 and 2.1.0 (EOL) allows authenticated attackers to define the storage location of report file pairs beyond their intended root directory.

Medienbericht Exploit
  • EPSS 0.24%
  • Veröffentlicht 09.10.2025 15:01:42
  • Zuletzt bearbeitet 04.12.2025 20:39:36

Use of an insecure temporary directory in the Windows License plugin for the Checkmk Windows Agent allows Privilege Escalation. This issue affects Checkmk: from 2.4.0 before 2.4.0p13, from 2.3.0 before 2.3.0p38, from 2.2.0 before 2.2.0p46, and all ve...

Medienbericht
  • EPSS 0.18%
  • Veröffentlicht 09.10.2025 15:00:58
  • Zuletzt bearbeitet 04.12.2025 20:44:21

Potential use of sensitive information in GET requests in Checkmk GmbH's Checkmk versions <2.4.0p13, <2.3.0p38, <2.2.0p46, and 2.1.0 (EOL) may cause sensitive form data to be included in URL query parameters, which may be logged in various places suc...

  • EPSS 0.33%
  • Veröffentlicht 04.07.2025 08:15:25
  • Zuletzt bearbeitet 22.08.2025 13:29:48

Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.