PT-2024-15070 · Checkmk · Checkmk

Published

2024-01-12

·

Updated

2024-07-23

·

CVE-2023-6740

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Checkmk versions prior to 2.2.0p18 Checkmk versions prior to 2.1.0p38 Checkmk versions prior to 2.0.0p39
Description The issue allows a local user to escalate privileges due to a problem in the jar signature agent plugin.
Recommendations For versions prior to 2.2.0p18, update to version 2.2.0p18 or later. For versions prior to 2.1.0p38, update to version 2.1.0p38 or later. For versions prior to 2.0.0p39, update to version 2.0.0p39 or later.

Fix

Improper Privilege Management

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2023-6740

Affected Products

Checkmk