Sensitive Information Exposure in Checkmk by Checkmk GmbH
CVE-2025-1075
5.6MEDIUM
What is CVE-2025-1075?
Certain versions of Checkmk software by Checkmk GmbH have a vulnerability that may lead to sensitive LDAP credentials being mistakenly logged in the Apache error log files. This issue affects versions below 2.3.0p27, versions below 2.2.0p40, and version 2.1.0p51, which has reached end-of-life. Administrators with access to these log files may inadvertently expose sensitive information, increasing the risk of unauthorized access.
Affected Version(s)
Checkmk 2.3.0 < 2.3.0p27
Checkmk 2.2.0 < 2.2.0p40
Checkmk 2.1.0 <= 2.1.0p50