Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
{
"unresolved_ranges": [
{
"cpe": "cpe:2.3:a:checkmk:checkmk:1.2.7:i4:*:*:*:*:*:*",
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "1.2.7-i4"
}
]
}
]
}{
"cpe": [
"cpe:2.3:a:checkmk:checkmk:1.2.3:i6:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.3:i7:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.4:b1:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i1:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i2:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i3:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i4:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i5:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.5:i6:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.6:b1:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.6:b2:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.6:p13:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.7:i1:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.7:i1p2:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.7:i2:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.7:i3:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.8:p18:*:*:*:*:*:*",
"cpe:2.3:a:checkmk:checkmk:1.2.8:p25:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "1.2.3-i6"
},
{
"last_affected": "1.2.3-i7"
},
{
"last_affected": "1.2.4-b1"
},
{
"last_affected": "1.2.5-i1"
},
{
"last_affected": "1.2.5-i2"
},
{
"last_affected": "1.2.5-i3"
},
{
"last_affected": "1.2.5-i4"
},
{
"last_affected": "1.2.5-i5"
},
{
"last_affected": "1.2.5-i6"
},
{
"last_affected": "1.2.6-b1"
},
{
"last_affected": "1.2.6-b2"
},
{
"last_affected": "1.2.6-p13"
},
{
"last_affected": "1.2.7-i1"
},
{
"last_affected": "1.2.7-i1p2"
},
{
"last_affected": "1.2.7-i2"
},
{
"last_affected": "1.2.7-i3"
},
{
"last_affected": "1.2.8-p18"
},
{
"last_affected": "1.2.8-p25"
}
]
}