PT-2025-17523 · Checkmk · Checkmk

Published

2025-04-22

·

Updated

2025-04-22

·

CVE-2025-2092

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmk versions <2.3.0p29 Checkmk versions <2.2.0p41 Checkmk versions <=2.1.0p49
Description The issue involves the insertion of sensitive information into log files in Checkmk, causing remote site authentication secrets to be written to log files accessible to administrators.
Recommendations For versions <2.3.0p29, update to version 2.3.0p29 or later. For versions <2.2.0p41, update to version 2.2.0p41 or later. For versions <=2.1.0p49, update to a version later than 2.1.0p49, or consider alternative measures as 2.1.0p49 is end-of-life.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2025-2092

Affected Products

Checkmk