CVE-2025-32915
- EPSS 0.12%
- Veröffentlicht 22.05.2025 14:16:01
- Zuletzt bearbeitet 26.08.2025 15:36:59
Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
CVE-2025-1712
- EPSS 0.66%
- Veröffentlicht 21.05.2025 09:10:42
- Zuletzt bearbeitet 22.08.2025 19:44:59
Argument injection in special agent configuration in Checkmk <2.4.0p1, <2.3.0p32, <2.2.0p42 and 2.1.0 allows authenticated attackers to write arbitrary files
CVE-2025-32917
- EPSS 0.26%
- Veröffentlicht 13.05.2025 10:45:31
- Zuletzt bearbeitet 22.08.2025 20:26:01
Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.
CVE-2025-3506
- EPSS 0.28%
- Veröffentlicht 08.05.2025 11:24:24
- Zuletzt bearbeitet 25.08.2025 14:51:47
Files to be deployed with agents are accessible without authentication in Checkmk 2.1.0, Checkmk 2.2.0, Checkmk 2.3.0 and <Checkmk 2.4.0b6 allows attacker to access files that could contain secrets.
CVE-2025-2092
- EPSS 0.25%
- Veröffentlicht 22.04.2025 11:38:04
- Zuletzt bearbeitet 25.08.2025 01:26:19
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p29, <2.2.0p41 and <=2.1.0p49 (EOL) causes remote site authentication secrets to be written to log files accessible to administrators.
CVE-2024-38865
- EPSS 0.64%
- Veröffentlicht 10.04.2025 07:35:35
- Zuletzt bearbeitet 21.08.2025 21:56:10
Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a cont...
CVE-2025-2596
- EPSS 0.18%
- Veröffentlicht 26.03.2025 10:51:16
- Zuletzt bearbeitet 25.08.2025 01:24:34
Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)
CVE-2025-1075
- EPSS 0.29%
- Veröffentlicht 19.02.2025 10:15:09
- Zuletzt bearbeitet 25.08.2025 01:19:09
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.
CVE-2024-38864
- EPSS 0.18%
- Veröffentlicht 19.12.2024 16:15:08
- Zuletzt bearbeitet 25.08.2025 14:53:51
Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.
CVE-2024-47094
- EPSS 0.21%
- Veröffentlicht 29.11.2024 10:15:10
- Zuletzt bearbeitet 03.12.2024 20:01:52
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.