Least privilege violation in the Checkmk agent plugins mk_oracle, mk_oracle.ps1, and mk_oracle_crs before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows local users to escalate privileges.
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
Link | Tags |
---|---|
https://checkmk.com/werk/16232 | vendor advisory |