Local File Access Vulnerability in Check_sftp
CVE-2024-28826
What is CVE-2024-28826?
A vulnerability exists in Checkmk that results from improper restrictions regarding local upload and download paths in the check_sftp functionality. This issue affects versions prior to 2.3.0p4, 2.2.0p27, and 2.1.0p44, as well as the End of Life version 2.0.0. Attackers with sufficient permissions can exploit this vulnerability to configure the check in a manner that allows unauthorized read and write access to local files on the Checkmk site server. This poses a significant security risk as sensitive data may be exposed or manipulated, potentially leading to further system compromise.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p4
Checkmk 2.2.0 < 2.2.0p27
Checkmk 2.1.0 < 2.1.0p44
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
