In Checkmk versions prior to 2.4.0p16, 2.3.0p41, and all versions of 2.2.0 and older, the mk_inotify plugin creates world-readable and writable files, allowing any local user on the system to read the plugin's output and manipulate it, potentially leading to unauthorized access to or modification of monitoring data.
References
| Link | Resource |
|---|---|
| https://checkmk.com/werk/18570 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-11-18 16:15
Updated : 2025-11-24 14:13
NVD link : CVE-2025-64996
Mitre link : CVE-2025-64996
CVE.ORG link : CVE-2025-64996
JSON object : View
Products Affected
checkmk
- checkmk
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
