Impact
Missing authorization for background jobs in Checkmk enables an authenticated user who knows a job identifier to retrieve the job’s status and output. The vulnerability does not allow arbitrary code execution or data modification; its impact is the unauthorized disclosure of potentially sensitive job information. This level of access could expose system operations, configurations, or other data that the job processes, but it remains limited to the job’s result set.
Affected Systems
Checkmk GmbH’s Checkmk product is affected in all releases prior to 2.5.0p12, 2.4.0p36, 2.3.0p50, and every 2.2.0 release. Users running those versions should review their installation and apply an update as soon as possible.
Risk and Exploitability
The CVSS score of 5.3 rates the issue as medium. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting a lower likelihood of widespread exploitation at this time. Nonetheless, any authenticated user with knowledge of a job ID can exercise this privilege, which may be leveraged by insiders or compromised credentials. The attack vector is local or over the network where the Checkmk service is exposed, and requires valid authentication to the Checkmk web interface.
OpenCVE Enrichment