Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-31207: Don't log automation user credentials when generating performance graph diagnostics

Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user’s secret to be written to the site Apache access log.

CVE
#vulnerability#apache

Component

Reporting & availability

Title

Don’t log automation user credentials when generating performance graph diagnostics

Date

Apr 24, 2023

Checkmk Edition

Checkmk Enterprise (CEE)

Checkmk Version

2.1.0p27

Level

Trivial Change

Class

Security Fix

Compatibility

Incompatible - Manual interaction might be required

Prior to this Werk, creating a Support Diagnostic report including the option "Performance Graphs of Checkmk Server" caused the automation secret of the user “automation” to be logged to the site Apache access log file (var/log/apache/access_log). This affected both creating the diagnostic report via the GUI (Setup > Maintenance > Support diagnostics) and via the command line (cmk --create-diagnostics-dump --performance-graphs).

With this Werk the credentials are no longer written to the log file. Note that no automatic sanitization of the log file is attempted by applying this patch.

This issue was discovered during internal review.

Affected Versions:

  • 2.2.0 (beta)
  • 2.1.0
  • 2.0.0

Mitigations: Users are advised to change the secret of the user “automation” via the User Management UI.

If this is not an option for you, delete or manually sanitize the Apache access log file and any backup of the file. Remove any line that contains a POST to /report.py?_username=automation&_secret=<…>.

Refrain from using the affected functionality before applying this patch or manually sanitize the file afterwards.

Vulnerability Management: We have rated the issue with a CVSS Score of 4.4 (Medium) with the following CVSS vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N. We have assigned CVE-2023-31207.

To the list of all Werks

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907