Local File Access Vulnerability in Check_sftp
CVE-2024-28826
8.1HIGH
What is CVE-2024-28826?
A vulnerability exists in Checkmk that results from improper restrictions regarding local upload and download paths in the check_sftp functionality. This issue affects versions prior to 2.3.0p4, 2.2.0p27, and 2.1.0p44, as well as the End of Life version 2.0.0. Attackers with sufficient permissions can exploit this vulnerability to configure the check in a manner that allows unauthorized read and write access to local files on the Checkmk site server. This poses a significant security risk as sensitive data may be exposed or manipulated, potentially leading to further system compromise.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p4
Checkmk 2.2.0 < 2.2.0p27
Checkmk 2.1.0 < 2.1.0p44