Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://checkmk.com/werk/17099 |
![]() ![]() |
History
Thu, 22 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 22 May 2025 14:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Packages downloaded by Checkmk's automatic agent updates on Linux and Solaris have incorrect permissions in Checkmk < 2.4.0p1, < 2.3.0p32, < 2.2.0p42 and <= 2.1.0p49 (EOL). This allows a local attacker to read sensitive data. | |
Title | Sensitive data exposed during automatic agent updates | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Checkmk
Published: 2025-05-22T14:16:01.214Z
Updated: 2025-05-22T14:48:38.894Z
Reserved: 2025-04-14T09:52:19.272Z
Link: CVE-2025-32915

Updated: 2025-05-22T14:48:33.722Z

Status : Awaiting Analysis
Published: 2025-05-22T15:16:04.870
Modified: 2025-05-23T15:55:02.040
Link: CVE-2025-32915

No data.