Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
References
Link | Resource |
---|---|
https://checkmk.com/werk/14916 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Configuration 3 (hide)
|
Information
Published : 2023-02-20 09:15
Updated : 2023-03-03 09:48
NVD link : CVE-2022-48319
Mitre link : CVE-2022-48319
JSON object : View
CWE
CWE-532
Insertion of Sensitive Information into Log File
Products Affected
tribe29
- checkmk