Least privilege violation and reliance on untrusted inputs in the mk_informix Checkmk agent plugin before Checkmk 2.3.0p12, 2.2.0p32, 2.1.0p47 and 2.0.0 (EOL) allows local users to escalate privileges.
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
Link | Tags |
---|---|
https://checkmk.com/werk/16249 | vendor advisory |