Checkmk
cpe:2.3:a:checkmk:checkmk:*:*:*:*:*:*:*
- >= 2.3.0, < 2.3.0p29
- >= 2.2.0, < 2.2.0p41
- >= 2.1.0, <= 2.1.0p49
A vulnerability exists in Checkmk versions prior to 2.3.0p29, prior to 2.2.0p41, and through 2.1.0p49 (EOL), allowing remote site authentication secrets to be inadvertently logged in files accessible to administrators. This issue arises when the log level for 'Web' is set to debug and the site interacts with remote sites, causing authentication secrets to be recorded in 'var/log/web.log'.
Exposed remote site authentication secrets in log files accessible to administrators.
Users can upgrade to Checkmk versions 2.3.0p29, 2.2.0p41, or 2.5.0b1. If an immediate upgrade is not possible, the log level can be changed to verbose or less to prevent sensitive information from being logged.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.