First published: Fri Mar 25 2022(Updated: )
The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tribe29 Checkmk | >=1.5.0<1.6.0 | |
Checkmk Checkmk | >=1.5.0<1.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40904 is a vulnerability in the web management console of CheckMK Raw Edition that allows a misconfiguration of the web-app Dokuwiki, resulting in remote code execution.
CVE-2021-40904 has a severity rating of 8.8 (high).
Versions 1.5.0 to 1.6.0 of the CheckMK Raw Edition are affected by CVE-2021-40904.
CVE-2021-40904 can be exploited by achieving access to the web management interface and exploiting a misconfiguration in the web-app Dokuwiki to execute remote code.
At the moment, there is no official fix available for CVE-2021-40904. It is recommended to keep the software up to date and apply any patches or security updates released by the vendor.