Werk #13321: NagVis: Updated to 1.9.29 (Fix possible deletion of arbitrary files)
Component | Other components |
Title | NagVis: Updated to 1.9.29 (Fix possible deletion of arbitrary files) |
Date | Dec 11, 2021 |
Checkmk Edition | Checkmk Raw (CRE) |
Checkmk Version | 1.6.0p28 2.0.0p18 2.1.0b1 |
Level | Trivial Change |
Class | Security Fix |
Compatibility | Compatible - no manual interaction needed |
Fix possible deletion of arbitrary files (CVE-2021-33178).
An authenticated user with enough permissions to access the NagVis. ManageBackgrounds endpoint, such as admin, can delete arbitrary files on the server limited by the rights of the Apache system user. In Checkmk, this is limited to files owned by the site user.
CVSS 3.1 base score: 4.5 (medium) CVSS 3.1 vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C
https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-33178