The Checkmk Conference #11 is happening – live on May 20-21! Watch now

Werk #13066: Fix path traversal vulnerability

Component Setup
Title Fix path traversal vulnerability
Date Jul 23, 2021
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.1.0b1 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
2.0.0p9 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
1.6.0p25 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)

An authenticated user was able to enumerate the filesystem, accessible to the siteuser. No file contents were disclosed.

To the list of all Werks