← Back

CVE-2017-14955

nvd nist
Published: Oct 2, 2017Modified: May 13, 2026

JSON object

Loading...
5.9
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.2 / Impact: 3.6
Source: NVD

Description

Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.

Affected (19)

Products: Checkmk: Checkmk
1 product
Checkmk
Configuration A
19 vulnerable
Vulnerable SoftwareAffected Versions
Checkmk
Version 1.2.3 i6
Version 1.2.3 i7
Version 1.2.4 b1
Version 1.2.5 i1
Version 1.2.5 i2
Version 1.2.5 i3
Version 1.2.5 i4
Version 1.2.5 i5
Version 1.2.5 i6
Version 1.2.6 b1
Version 1.2.6 b2
Version 1.2.6 p13
Version 1.2.7 i1
Version 1.2.7 i1p2
Version 1.2.7 i2
Version 1.2.7 i3
Version 1.2.7 i4
Version 1.2.8 p18
Version 1.2.8 p25

References (6)

Source: cve@mitre.org
Release NotesThird Party Advisory
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.