Werk #14916: Do not log host secret

Component Agent bakery
Title Do not log host secret
Date Oct 7, 2022
Checkmk Editon Checkmk Enterprise (CEE)
Checkmk Version 2.2.0i1 2.1.0p14 2.0.0p30
Level Major Change
Class Security Fix
Compatibility Incompatible - Manual interaction might be required

When using the Agent updater the Checkmk server needs a secret in order to allow the agent to download new agents. For security reasons this secret is unique for each host and generated with the cmk-update-agent register command. Unfortunately the generated host secret was written to the cmk-update-agent.log. This logfile is not protected and usually world-readable.

With this secret one can download the current agent from the Checkmk server. Included in that agent package are the plugin configs which can contain other secrets. (e.g. database credentials)

Mitigations without updateing:

  • Reregister the agent-updater. Then sanitize the cmk-update-agent.log files.
  • If you cannot rule out that any unauthorized user read /var/lib/check_mk_agent/cmk-update-agent.log respectively C:\ProgramData\checkmk\agent\log\cmk-update-agent.log you should rotate all secrets that might be or were included in the agent configurations.

Steps needed with the update:

  • Update your agent.
  • Reregister the agent-updater.

All versions including 1.5 are subject to this vulnerability.

We found this vulnerability internally and have no indication of any exploitation.

We calculated a CVSS 3.1 score of 6.5 (Medium) with the following vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

To the list of all Werks