Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.2.3-i6"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.3-i7"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.4-b1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i3"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i4"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i5"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.5-i6"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.6-b1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.6-b2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.6-p13"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.7-i1"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.7-i1p2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.7-i2"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.7-i3"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.8-p18"
},
{
"introduced": "0"
},
{
"last_affected": "1.2.8-p25"
}
]
}