Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c7vr-4qg5-q9v7

Опубликовано: 20 фев. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 5.5

Описание

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

EPSS

Процентиль: 25%
0.00086
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 3 года назад

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

CVSS3: 6.5
nvd
почти 3 года назад

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.

CVSS3: 6.5
debian
почти 3 года назад

Sensitive host secret disclosed in cmk-update-agent.log file in Tribe2 ...

EPSS

Процентиль: 25%
0.00086
Низкий

5.5 Medium

CVSS3

Дефекты

CWE-200
CWE-532