CVE-2024-38862: SNMP and IMPI secrets written to audit log
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p18, <2.2.0p35, <2.1.0p48 and <=2.0.0p39 (EOL) causes SNMP and IMPI secrets of host and folder properties to be written to audit log files accessible to administrators.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38862?
CVE-2024-38862 has been assigned a medium severity level due to the exposure of sensitive information in log files.
How do I fix CVE-2024-38862?
To fix CVE-2024-38862, update your Checkmk installation to version 2.3.0p18 or newer, or the respective patched versions for earlier releases.
What information is exposed in CVE-2024-38862?
CVE-2024-38862 allows for the exposure of SNMP and IMPI secrets from host and folder properties in audit log files.
Which versions of Checkmk are affected by CVE-2024-38862?
CVE-2024-38862 affects Checkmk versions older than 2.3.0p18, 2.2.0p35, 2.1.0p48, and 2.0.0p39.
Who is potentially affected by CVE-2024-38862?
Administrators of affected Checkmk versions could be impacted by CVE-2024-38862 due to unauthorized access to sensitive log information.