Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://checkmk.com/werk/16163 | patch vendor advisory |