PT-2023-15696 · Checkmk · Checkmk

Published

2023-02-20

·

Updated

2024-07-23

·

CVE-2022-48319

CVSS v3.1

6.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions 1.6.0 and earlier Checkmk versions 2.0.0 through 2.0.0p29 Checkmk versions 2.1.0 through 2.1.0p13
Description A sensitive host secret is disclosed in the cmk-update-agent.log file, allowing an attacker to gain access to the host secret through the unprotected agent updater log file.
Recommendations For Checkmk versions 1.6.0 and earlier, there is no information about a newer version that contains a fix for this vulnerability. For Checkmk versions 2.0.0 through 2.0.0p29, update to a version later than 2.0.0p29. For Checkmk versions 2.1.0 through 2.1.0p13, update to a version later than 2.1.0p13. As a temporary workaround, consider restricting access to the cmk-update-agent.log file to minimize the risk of exploitation.

Insertion into Log File

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-48319

Affected Products

Checkmk