CVE-2024-38862
- EPSS 0.32%
- Veröffentlicht 14.10.2024 08:15:02
- Zuletzt bearbeitet 29.04.2026 01:00:01
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to adminis...
CVE-2024-38863
- EPSS 0.41%
- Veröffentlicht 14.10.2024 08:15:02
- Zuletzt bearbeitet 29.04.2026 01:00:01
Exposure of CSRF tokens in query parameters on specific requests in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35 and <2.1.0p48 could lead to a leak of the token to facilitate targeted phishing attacks.
CVE-2024-6747
- EPSS 0.37%
- Veröffentlicht 10.10.2024 08:15:03
- Zuletzt bearbeitet 15.10.2024 13:22:17
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data
CVE-2024-8606
- EPSS 0.45%
- Veröffentlicht 23.09.2024 07:15:02
- Zuletzt bearbeitet 30.09.2024 15:32:34
Bypass of two factor authentication in RestAPI in Checkmk < 2.3.0p16 and < 2.2.0p34 allows authenticated users to bypass two factor authentication
CVE-2024-38860
- EPSS 0.31%
- Veröffentlicht 17.09.2024 14:15:17
- Zuletzt bearbeitet 11.12.2024 03:01:28
Improper neutralization of input in Checkmk before versions 2.3.0p16 and 2.2.0p34 allows attackers to craft malicious links that can facilitate phishing attacks.
CVE-2024-6572
- EPSS 0.34%
- Veröffentlicht 09.09.2024 10:15:01
- Zuletzt bearbeitet 25.08.2025 14:53:24
Improper host key checking in active check 'Check SFTP Service' and special agent 'VNX quotas and filesystem' in Checkmk before Checkmk 2.3.0p15, 2.2.0p33, 2.1.0p48 and 2.0.0 (EOL) allows man-in-the-middle attackers to intercept traffic
CVE-2024-38858
- EPSS 0.31%
- Veröffentlicht 02.09.2024 12:15:19
- Zuletzt bearbeitet 04.09.2024 14:39:10
Improper neutralization of input in Checkmk before version 2.3.0p14 allows attackers to inject and run malicious scripts in the Robotmk logs view.
CVE-2024-38859
- EPSS 0.42%
- Veröffentlicht 26.08.2024 15:15:08
- Zuletzt bearbeitet 03.12.2024 17:47:02
XSS in the view page with the SLA column configured in Checkmk versions prior to 2.3.0p14, 2.2.0p33, 2.1.0p47 and 2.0.0 (EOL) allowed malicious users to execute arbitrary scripts by injecting HTML elements into the SLA column title. These scripts cou...
CVE-2024-28829
- EPSS 0.18%
- Veröffentlicht 20.08.2024 10:15:05
- Zuletzt bearbeitet 03.12.2024 17:55:48
Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
CVE-2024-6542
- EPSS 0.47%
- Veröffentlicht 22.07.2024 10:15:08
- Zuletzt bearbeitet 21.11.2024 09:49:50
Improper neutralization of livestatus command delimiters in mknotifyd in Checkmk <= 2.0.0p39, < 2.1.0p47, < 2.2.0p32 and < 2.3.0p11 allows arbitrary livestatus command execution.