Checkmk

Checkmk

114 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.79%
  • Veröffentlicht 10.04.2025 07:35:35
  • Zuletzt bearbeitet 21.08.2025 21:56:10

Improper neutralization of livestatus command delimiters in a specific endpoint within RestAPI of Checkmk prior to 2.2.0p39, 2.3.0p25, and 2.1.0p51 (EOL) allows arbitrary livestatus command execution. Exploitation requires the attacker to have a cont...

  • EPSS 0.2%
  • Veröffentlicht 26.03.2025 10:51:16
  • Zuletzt bearbeitet 25.08.2025 01:24:34

Session logout could be overwritten in Checkmk GmbH's Checkmk versions <2.3.0p30, <2.2.0p41, and 2.1.0p49 (EOL)

  • EPSS 0.31%
  • Veröffentlicht 19.02.2025 10:15:09
  • Zuletzt bearbeitet 25.08.2025 01:19:09

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p27, <2.2.0p40, and 2.1.0p51 (EOL) causes LDAP credentials to be written to Apache error log file accessible to administrators.

  • EPSS 0.18%
  • Veröffentlicht 19.12.2024 16:15:08
  • Zuletzt bearbeitet 25.08.2025 14:53:51

Incorrect permissions on the Checkmk Windows Agent's data directory in Checkmk < 2.3.0p23, < 2.2.0p38 and <= 2.1.0p49 (EOL) allows a local attacker to read sensitive data.

  • EPSS 0.21%
  • Veröffentlicht 29.11.2024 10:15:10
  • Zuletzt bearbeitet 03.12.2024 20:01:52

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.

  • EPSS 0.32%
  • Veröffentlicht 14.10.2024 08:15:02
  • Zuletzt bearbeitet 29.04.2026 01:00:01

Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to adminis...

  • EPSS 0.42%
  • Veröffentlicht 14.10.2024 08:15:02
  • Zuletzt bearbeitet 29.04.2026 01:00:01

Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.

  • EPSS 0.38%
  • Veröffentlicht 10.10.2024 08:15:03
  • Zuletzt bearbeitet 15.10.2024 13:22:17

Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data

  • EPSS 0.46%
  • Veröffentlicht 23.09.2024 07:15:02
  • Zuletzt bearbeitet 30.09.2024 15:32:34

Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication

  • EPSS 0.31%
  • Veröffentlicht 17.09.2024 14:15:17
  • Zuletzt bearbeitet 11.12.2024 03:01:28

Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.