Local File Access Vulnerability in Check_sftp
CVE-2024-28826

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
29 May 2024

Summary

A vulnerability exists in Checkmk that results from improper restrictions regarding local upload and download paths in the check_sftp functionality. This issue affects versions prior to 2.3.0p4, 2.2.0p27, and 2.1.0p44, as well as the End of Life version 2.0.0. Attackers with sufficient permissions can exploit this vulnerability to configure the check in a manner that allows unauthorized read and write access to local files on the Checkmk site server. This poses a significant security risk as sensitive data may be exposed or manipulated, potentially leading to further system compromise.

Affected Version(s)

Checkmk 2.3.0 < 2.3.0p4

Checkmk 2.2.0 < 2.2.0p27

Checkmk 2.1.0 < 2.1.0p44

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.