ZeroHour

CVE-2024-28826

CVSS 3.1
8.1 high
EPSS
<1%p40
Published
()
Modified
Description

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.

Vendors
checkmk
Products
checkmk
Weakness
CWE-73, CWE-610
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.