Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://checkmk.com/werk/15200 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: Checkmk
Published: 2024-05-29T10:00:53.789Z
Updated: 2024-08-02T00:56:58.127Z
Reserved: 2024-03-11T13:21:43.122Z
Link: CVE-2024-28826
Vulnrichment
Updated: 2024-06-05T20:33:00.647Z
NVD
Status : Awaiting Analysis
Published: 2024-05-29T10:15:09.010
Modified: 2024-11-21T09:07:00.493
Link: CVE-2024-28826
Redhat
No data.