The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
http://checkmk.com |
![]() ![]() ![]() |
https://github.com/Edgarloyola/CVE-2021-40905 |
![]() ![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T02:51:07.760Z
Reserved: 2021-09-13T00:00:00
Link: CVE-2021-40905

Updated: 2024-08-04T02:51:07.760Z

Status : Modified
Published: 2022-03-25T23:15:08.237
Modified: 2024-11-21T06:25:04.480
Link: CVE-2021-40905

No data.

No data.