PT-2022-20645 · Checkmk · Checkmk

Timo Klecker

·

Published

2022-05-20

·

Updated

2024-07-23

·

CVE-2022-31258

CVSS v3.1

8.2

High

VectorAC:L/AV:L/A:H/C:H/I:H/PR:H/S:C/UI:N
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 1.6.0p29 Checkmk versions 2.x prior to 2.0.0p25 Checkmk versions 2.1.x prior to 2.1.0b10
Description A site user can escalate to root by editing an OMD hook symlink.
Recommendations For Checkmk versions prior to 1.6.0p29, update to version 1.6.0p29 or later. For Checkmk versions 2.x prior to 2.0.0p25, update to version 2.0.0p25 or later. For Checkmk versions 2.1.x prior to 2.1.0b10, update to version 2.1.0b10 or later.

Fix

Link Following

Weakness Enumeration

Related Identifiers

CVE-2022-31258

Affected Products

Checkmk