CVE-2017-14955

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:tribe29:checkmk:1.2.5:i4:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.5:i5:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.5:i6:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.6:b1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.5:i1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.5:i3:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.6:b2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.7:i1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.7:i2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.3:i6:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.3:i7:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.8:p25:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.4:b1:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.5:i2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.6:p13:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.7:i1p2:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.7:i3:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.7:i4:*:*:*:*:*:*
cpe:2.3:a:tribe29:checkmk:1.2.8:p18:*:*:*:*:*:*

Information

Published : 2017-10-01 18:29

Updated : 2019-10-17 06:21


NVD link : CVE-2017-14955

Mitre link : CVE-2017-14955


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Advertisement

dedicated server usa

Products Affected

tribe29

  • checkmk