CVE-2022-48319: Checkmk
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
Affected products
- Checkmk Checkmk: version 2.1.0 only; version 2.0.0 only; version 1.6.0 only
Published 2023-02-20. Last modified 2026-06-17.