CVE-2022-48319

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2022-48319
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-48319.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-48319
Published
2023-02-20T17:15:12Z
Modified
2024-06-20T02:09:53.249153Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

References

Affected packages

Git / github.com/tribe29/checkmk

Affected ranges

Type
GIT
Repo
https://github.com/tribe29/checkmk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected

Affected versions

1.*

1.1.0beta17

v1.*

v1.1.0
v1.1.10
v1.1.10b1
v1.1.10b2
v1.1.11i1
v1.1.11i2
v1.1.11i3
v1.1.11i4
v1.1.12
v1.1.12b1
v1.1.12b2
v1.1.13i1
v1.1.13i2
v1.1.13i3
v1.1.2
v1.1.3
v1.1.3b1
v1.1.4
v1.1.5i0
v1.1.5i1
v1.1.5i2
v1.1.5i3
v1.1.6
v1.1.6b2
v1.1.6b3
v1.1.7i1
v1.1.7i2
v1.1.7i3
v1.1.7i4
v1.1.7i5
v1.1.8
v1.1.8b1
v1.1.8b2
v1.1.8b3
v1.1.9i1
v1.1.9i2
v1.1.9i3
v1.1.9i4
v1.1.9i5
v1.1.9i6
v1.1.9i7
v1.1.9i8
v1.1.9i9
v1.2.0b1
v1.2.0b2
v1.2.0b3
v1.2.0b4
v1.2.0b5
v1.2.0b6
v1.2.0p1
v1.2.0p2
v1.2.0p3
v1.2.1i1
v1.2.1i2
v1.2.1i3
v1.2.1i4
v1.2.1i5
v1.2.2b1
v1.2.3i1
v1.2.3i2
v1.2.3i3
v1.2.3i4
v1.2.3i5
v1.2.3i6
v1.2.3i7
v1.2.5i1
v1.2.5i2
v1.2.5i3
v1.2.5i4
v1.2.5i5
v1.2.5i6
v1.2.7i1
v1.2.7i2
v1.2.7i3
v1.4.0i1
v1.4.0i2
v1.4.0i3
v1.5.0i1
v1.5.0i2
v1.5.0i3
v1.6.0
v1.6.0b1
v1.6.0b10
v1.6.0b11
v1.6.0b2
v1.6.0b3
v1.6.0b4
v1.6.0b5
v1.6.0b6
v1.6.0b7
v1.6.0b8
v1.6.0b9

v2.*

v2.0.0
v2.0.0b1
v2.0.0b2
v2.0.0b3
v2.0.0b4
v2.0.0b5
v2.0.0b6
v2.0.0b7
v2.0.0i1
v2.1.0
v2.1.0b1
v2.1.0b2
v2.1.0b3
v2.1.0b4
v2.1.0b5
v2.1.0b6
v2.1.0b7
v2.1.0b8
v2.1.0b9