CVE-2017-14955

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:checkmk:checkmk:1.2.3:i6:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.3:i7:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.4:b1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i4:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i5:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.5:i6:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.6:b1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.6:b2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.6:p13:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.7:i1:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.7:i1p2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.7:i2:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.7:i3:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.7:i4:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.8:p18:*:*:*:*:*:*
cpe:2.3:a:checkmk:checkmk:1.2.8:p25:*:*:*:*:*:*

History

No history.

Information

Published : 2017-10-02 01:29

Updated : 2024-07-23 19:37


NVD link : CVE-2017-14955

Mitre link : CVE-2017-14955

CVE.ORG link : CVE-2017-14955


JSON object : View

Products Affected

checkmk

  • checkmk
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-362

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')