Werk #13321: NagVis: Updated to 1.9.29 (Fix possible deletion of arbitrary files)

Component Other components
Title NagVis: Updated to 1.9.29 (Fix possible deletion of arbitrary files)
Date Dec 11, 2021
Level Trivial Change
Class Security Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.1.0b1 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
2.0.0p18 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)
1.6.0p28 Checkmk Raw (CRE), Checkmk Enterprise (CEE), Checkmk MSP (CME)

Fix possible deletion of arbitrary files (CVE-2021-33178).

An authenticated user with enough permissions to access the NagVis. ManageBackgrounds endpoint, such as admin, can delete arbitrary files on the server limited by the rights of the Apache system user. In Checkmk, this is limited to files owned by the site user.

CVSS 3.1 base score: 4.5 (medium) CVSS 3.1 vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C

https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33178

To the list of all Werks