PT-2023-15696 · Checkmk · Checkmk

CVE-2022-48319

·

Publicado

2023-02-20

·

Atualizado

2024-07-23

CVSS v3.1

6.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 1.6.0 and earlier Checkmk versions 2.0.0 through 2.0.0p29 Checkmk versions 2.1.0 through 2.1.0p13
Description A sensitive host secret is disclosed in the cmk-update-agent.log file, allowing an attacker to gain access to the host secret through the unprotected agent updater log file.
Recommendations For Checkmk versions 1.6.0 and earlier, there is no information about a newer version that contains a fix for this vulnerability. For Checkmk versions 2.0.0 through 2.0.0p29, update to a version later than 2.0.0p29. For Checkmk versions 2.1.0 through 2.1.0p13, update to a version later than 2.1.0p13. As a temporary workaround, consider restricting access to the cmk-update-agent.log file to minimize the risk of exploitation.

Insertion into Log File

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-48319

Produtos afetados

Checkmk