CVE-2024-28829

Aug. 20, 2024, 3:44 p.m.

None
No Score

Description

Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.

Product(s) Impacted

Product Versions
Checkmk
  • before 2.3.0p12
  • before 2.2.0p32
  • before 2.1.0p47
  • 2.0.0 (EOL)

Weaknesses

CWE-272
Least Privilege Violation
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.

Date

  • Published: Aug. 20, 2024, 10:15 a.m.
  • Last Modified: Aug. 20, 2024, 3:44 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

security@checkmk.com

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.