SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was deployed.
References
| Link | Resource |
|---|---|
| https://checkmk.com/werk/19030 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2025-12-18 14:15
Updated : 2025-12-23 17:04
NVD link : CVE-2025-65000
Mitre link : CVE-2025-65000
CVE.ORG link : CVE-2025-65000
JSON object : View
Products Affected
checkmk
- checkmk
CWE
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
