Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

Ubuntu 18.04 LTS: USN-5527-1 Critical Checkmk Authentication Flaws

Ubuntu Large Esm H500
Several security issues were fixed in Checkmk.
=========================================================================Ubuntu Security Notice USN-5527-1
July 20, 2022

check-mk vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 18.04 LTS

Summary:

Several security issues were fixed in Checkmk.

Software Description:
- check-mk: general purpose monitoring plugin for retrieving data

Details:

It was discovered that Checkmk incorrectly handled authentication. An attacker 
could possibly use this issue to cause a race condition leading to information 
disclosure. (CVE-2017-14955)

It was discovered that Checkmk incorrectly handled certain inputs. An attacker
could use these cross-site scripting issues to inject arbitrary html or 
javascript code to obtain sensitive information including user information, 
session cookies and valid credentials. (CVE-2017-9781, CVE-2021-36563, 
CVE-2021-40906, CVE-2022-24565)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  check-mk-livestatus             1.2.8p16-1ubuntu0.2
  check-mk-multisite              1.2.8p16-1ubuntu0.2
  check-mk-server                 1.2.8p16-1ubuntu0.2

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-5527-1
  CVE-2017-14955, CVE-2017-9781, CVE-2021-36563, CVE-2021-40906,
  CVE-2022-24565

Package Information:
  https://launchpad.net/ubuntu/+source/check-mk/1.2.8p16-1ubuntu0.2

Ubuntu 18.04 LTS: USN-5527-1 Critical Checkmk Authentication Flaws

ubuntu
Calendar Grey July 20, 2022
Dist Ubuntu Esm H88
Critical vulnerabilities in Checkmk on Ubuntu could compromise security, allowing unauthorized access and data manipulation. Immediate updates and strong security practices recommended
Several security issues were fixed in Checkmk.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 18.04 LTS: check-mk-livestatus 1.2.8p16-1ubuntu0.2 check-mk-multisite 1.2.8p16-1ubuntu0.2 check-mk-server 1.2.8p16-1ubuntu0.2 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-5527-1

CVE-2017-14955, CVE-2017-9781, CVE-2021-36563, CVE-2021-40906,

CVE-2022-24565

Severity
critical
Lowest
Low
Medium
High
Critical

July 20, 2022

Package Information

https://launchpad.net/ubuntu/+source/check-mk/1.2.8p16-1ubuntu0.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here