Privilege escalation in jar_signature
CVE-2023-6740

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
12 January 2024

What is CVE-2023-6740?

The jar_signature agent plugin in Checkmk versions prior to 2.2.0p18, 2.1.0p38, and 2.0.0p39 contains a vulnerability that permits local users to escalate their privileges. This flaw can be exploited by an authenticated local user, potentially enabling unauthorized access to sensitive operations within the Checkmk environment. Administrators are encouraged to update their installations to the latest versions to mitigate the risk associated with this vulnerability, as it poses significant security implications for the integrity of system access management.

Affected Version(s)

Checkmk 2.2.0 < 2.2.0p18

Checkmk 2.1.0 < 2.1.0p38

Checkmk 2.0.0 <= 2.0.0p39

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.