CVE-2024-28829: Privilege escalation in mk_informix plugin
Least privilege violation and reliance on untrusted inputs in the mkinformix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28829?
CVE-2024-28829 is classified as a local privilege escalation vulnerability due to least privilege violation.
How do I fix CVE-2024-28829?
To resolve CVE-2024-28829, upgrade to Checkmk versions 2.3.0p12 or later, 2.2.0p32 or later, or 2.1.0p47 or later.
What are the affected versions in CVE-2024-28829?
CVE-2024-28829 affects Checkmk versions 2.0.0, 2.1.0, 2.2.0, and versions before 2.3.0p12.
Who is at risk for CVE-2024-28829?
Local users with access to the vulnerable Checkmk agent plugin are at risk of privilege escalation due to CVE-2024-28829.
What is the nature of the vulnerability in CVE-2024-28829?
CVE-2024-28829 involves a least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin.