Security Advisory

CVE-2024-28826

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-05-29 10:00:53
Last updated 2024-08-02 00:56:58
Assigner Checkmk
State PUBLISHED

Description

Improper restriction of local upload and download paths in check_sftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.