PT-2022-20645 · Checkmk · Checkmk
Timo Klecker
·
Published
2022-05-20
·
Updated
2024-07-23
·
CVE-2022-31258
CVSS v3.1
8.2
High
| Vector | AC:L/AV:L/A:H/C:H/I:H/PR:H/S:C/UI:N |
Name of the Vulnerable Software and Affected Versions
Checkmk versions prior to 1.6.0p29
Checkmk versions 2.x prior to 2.0.0p25
Checkmk versions 2.1.x prior to 2.1.0b10
Description
A site user can escalate to root by editing an OMD hook symlink.
Recommendations
For Checkmk versions prior to 1.6.0p29, update to version 1.6.0p29 or later.
For Checkmk versions 2.x prior to 2.0.0p25, update to version 2.0.0p25 or later.
For Checkmk versions 2.1.x prior to 2.1.0b10, update to version 2.1.0b10 or later.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmk