CVE-2017-14955: Infoleak
Published Oct 1, 2017
·Updated
CheckMK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
Affected Software
38 affected components
Tribe29 Checkmk=1.2.3-i6
Tribe29 Checkmk=1.2.3-i7
Tribe29 Checkmk=1.2.4-b1
Tribe29 Checkmk=1.2.5-i1
Tribe29 Checkmk=1.2.5-i2
Tribe29 Checkmk=1.2.5-i3
Tribe29 Checkmk=1.2.5-i4
Tribe29 Checkmk=1.2.5-i5
Tribe29 Checkmk=1.2.5-i6
Tribe29 Checkmk=1.2.6-b1
Tribe29 Checkmk=1.2.6-b2
Tribe29 Checkmk=1.2.6-p13
Tribe29 Checkmk=1.2.7-i1
Tribe29 Checkmk=1.2.7-i1p2
Tribe29 Checkmk=1.2.7-i2
Tribe29 Checkmk=1.2.7-i3
Tribe29 Checkmk=1.2.7-i4
Tribe29 Checkmk=1.2.8-p18
Tribe29 Checkmk=1.2.8-p25
CheckMK Checkmk=1.2.3-i6
CheckMK Checkmk=1.2.3-i7
CheckMK Checkmk=1.2.4-b1
CheckMK Checkmk=1.2.5-i1
CheckMK Checkmk=1.2.5-i2
CheckMK Checkmk=1.2.5-i3
CheckMK Checkmk=1.2.5-i4
CheckMK Checkmk=1.2.5-i5
CheckMK Checkmk=1.2.5-i6
CheckMK Checkmk=1.2.6-b1
CheckMK Checkmk=1.2.6-b2
CheckMK Checkmk=1.2.6-p13
CheckMK Checkmk=1.2.7-i1
CheckMK Checkmk=1.2.7-i1p2
CheckMK Checkmk=1.2.7-i2
CheckMK Checkmk=1.2.7-i3
CheckMK Checkmk=1.2.7-i4
CheckMK Checkmk=1.2.8-p18
CheckMK Checkmk=1.2.8-p25
Event History
Oct 1, 2017
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-14955?
CVE-2017-14955 is rated as a medium severity vulnerability due to its potential to expose sensitive user information.
2
How do I fix CVE-2017-14955?
To fix CVE-2017-14955, update your Check_MK installation to version 1.2.8p26 or later.
3
What type of vulnerability is CVE-2017-14955?
CVE-2017-14955 is a race condition vulnerability that affects the failed-login save feature in Check_MK.
4
What impact does CVE-2017-14955 have on users?
CVE-2017-14955 allows remote attackers to access sensitive user information through a GUI crash report.
5
Which versions of Check_MK are affected by CVE-2017-14955?
CVE-2017-14955 affects Check_MK versions prior to 1.2.8p26, including several earlier versions.