CVE-2017-14955: Infoleak

Published Oct 1, 2017
·
Updated

CheckMK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

Affected Software

38 affected components
Tribe29 Checkmk=1.2.3-i6
Tribe29 Checkmk=1.2.3-i7
Tribe29 Checkmk=1.2.4-b1
Tribe29 Checkmk=1.2.5-i1
Tribe29 Checkmk=1.2.5-i2
Tribe29 Checkmk=1.2.5-i3
Tribe29 Checkmk=1.2.5-i4
Tribe29 Checkmk=1.2.5-i5
Tribe29 Checkmk=1.2.5-i6
Tribe29 Checkmk=1.2.6-b1
Tribe29 Checkmk=1.2.6-b2
Tribe29 Checkmk=1.2.6-p13
Tribe29 Checkmk=1.2.7-i1
Tribe29 Checkmk=1.2.7-i1p2
Tribe29 Checkmk=1.2.7-i2
Tribe29 Checkmk=1.2.7-i3
Tribe29 Checkmk=1.2.7-i4
Tribe29 Checkmk=1.2.8-p18
Tribe29 Checkmk=1.2.8-p25
CheckMK Checkmk=1.2.3-i6
CheckMK Checkmk=1.2.3-i7
CheckMK Checkmk=1.2.4-b1
CheckMK Checkmk=1.2.5-i1
CheckMK Checkmk=1.2.5-i2
CheckMK Checkmk=1.2.5-i3
CheckMK Checkmk=1.2.5-i4
CheckMK Checkmk=1.2.5-i5
CheckMK Checkmk=1.2.5-i6
CheckMK Checkmk=1.2.6-b1
CheckMK Checkmk=1.2.6-b2
CheckMK Checkmk=1.2.6-p13
CheckMK Checkmk=1.2.7-i1
CheckMK Checkmk=1.2.7-i1p2
CheckMK Checkmk=1.2.7-i2
CheckMK Checkmk=1.2.7-i3
CheckMK Checkmk=1.2.7-i4
CheckMK Checkmk=1.2.8-p18
CheckMK Checkmk=1.2.8-p25

Event History

Oct 1, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-14955?

CVE-2017-14955 is rated as a medium severity vulnerability due to its potential to expose sensitive user information.

2

How do I fix CVE-2017-14955?

To fix CVE-2017-14955, update your Check_MK installation to version 1.2.8p26 or later.

3

What type of vulnerability is CVE-2017-14955?

CVE-2017-14955 is a race condition vulnerability that affects the failed-login save feature in Check_MK.

4

What impact does CVE-2017-14955 have on users?

CVE-2017-14955 allows remote attackers to access sensitive user information through a GUI crash report.

5

Which versions of Check_MK are affected by CVE-2017-14955?

CVE-2017-14955 affects Check_MK versions prior to 1.2.8p26, including several earlier versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203