CVE-2024-28826: Unrestricted upload and download paths in check_sftp
Improper restriction of local upload and download paths in checksftp in Checkmk before 2.3.0p4, 2.2.0p27, 2.1.0p44, and in Checkmk 2.0.0 (EOL) allows attackers with sufficient permissions to configure the check to read and write local files on the Checkmk site server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28826?
CVE-2024-28826 has a high severity rating due to its potential to allow unauthorized file access on the Checkmk site server.
How do I fix CVE-2024-28826?
To fix CVE-2024-28826, upgrade to Checkmk version 2.3.0p4, 2.2.0p27, or 2.1.0p44 or a later version.
What type of vulnerability is CVE-2024-28826?
CVE-2024-28826 is classified as a privilege escalation vulnerability affecting configuration settings.
Who is affected by CVE-2024-28826?
CVE-2024-28826 affects users of Checkmk versions prior to 2.3.0p4, 2.2.0p27, and 2.1.0p44.
What does CVE-2024-28826 allow attackers to do?
CVE-2024-28826 allows attackers with sufficient permissions to read and write local files on the Checkmk site server.