CVE-2024-28830: Automation user secrets written to audit log
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p7, <2.2.0p28, <2.1.0p45 and <=2.0.0p39 (EOL) causes automation user secrets to be written to audit log files accessible to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-28830?
The severity of CVE-2024-28830 is considered high due to the exposure of sensitive automation user secrets in audit logs.
How do I fix CVE-2024-28830?
To fix CVE-2024-28830, upgrade to Checkmk version 2.3.0p7 or later, or to 2.2.0p28, 2.1.0p45, or any version higher than 2.0.0p39.
What versions of Checkmk are affected by CVE-2024-28830?
CVE-2024-28830 affects Checkmk versions earlier than 2.3.0p7, 2.2.0p28, 2.1.0p45, and all 2.0.0 versions.
What types of information are leaked in CVE-2024-28830?
CVE-2024-28830 leads to the leak of sensitive automation user secrets into audit log files.
Who can access the logs affected by CVE-2024-28830?
The audit log files containing the sensitive information due to CVE-2024-28830 are accessible to administrators.