CheckMK before 1.2.4p4 and 1.2.5 before 1.2.5i4 allows remote authenticated users to write checkmk config files (.mk files) to arbitrary locations via vectors related to row selections.
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "check-mk-agent",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-agent-logwatch",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-config-icinga",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-config-nagios3",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-doc",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-livestatus",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-livestatus-dbgsym",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-multisite",
"binary_version": "1.2.6p12-1"
},
{
"binary_name": "check-mk-server",
"binary_version": "1.2.6p12-1"
}
]
}