{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/checkmk--1.7.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:aiohttp:aiohttp:*:*:*:*:*:*:*:*","cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*","cpe:2.3:a:mybb:mybb:*:*:*:*:*:*:*:*","cpe:2.3:a:jqlang:jq:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":5.9,"id":"CVE-2024-23334"},{"id":"CVE-2024-23338"},{"cvss":4.7,"id":"CVE-2024-23335"},{"cvss":5,"id":"CVE-2024-23336"},{"cvss":4.3,"id":"CVE-2024-23337"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Checkmk (\u003c= 1.7.1)","Checkmk"],"_cs_severities":["high"],"_cs_tags":["vulnerability","web-application","monitoring","privilege-escalation","local-attack"],"_cs_type":"advisory","_cs_vendors":["Checkmk"],"content_html":"\u003cp\u003eCheckmk has been identified as vulnerable to a series of security flaws categorized as CVE-2024-23334, CVE-2024-23335, CVE-2024-23336, CVE-2024-23337, and CVE-2024-23338. These vulnerabilities affect the core functionality of the Checkmk monitoring platform. Depending on the specific vulnerability, attackers may be able to execute cross-site scripting (XSS) attacks, gain unauthorized access to sensitive system information, or manipulate monitoring data within the application. These flaws pose a significant risk to the integrity and confidentiality of monitoring environments. Defenders should identify all instances of Checkmk across their infrastructure and apply the vendor-supplied security patches to mitigate the risk of exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to unauthorized data access, the manipulation of monitoring configurations, or the compromise of user sessions through XSS. This could impact the availability and reliability of infrastructure monitoring services and potentially facilitate further attacks if internal data is exposed to unauthorized parties.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all Checkmk instances in the production environment. Apply vendor-provided security updates immediately to address CVE-2024-23334, CVE-2024-23335, CVE-2024-23336, CVE-2024-23337, and CVE-2024-23338. Review web server access logs for anomalous patterns targeting Checkmk directories, particularly those involving unexpected script injection or unauthorized attempts to access configuration files.\u003c/p\u003e\n","date_modified":"2026-10-08T19:22:16Z","date_published":"2026-10-06T12:43:33Z","id":"https://feed.craftedsignal.io/briefs/2026-10-checkmk-vulnerabilities/","summary":"Checkmk is affected by multiple vulnerabilities, including CVE-2024-23334 through CVE-2024-23338, which may allow unauthenticated or authenticated attackers to perform cross-site scripting, information disclosure, or data manipulation.","title":"Multiple Vulnerabilities in Checkmk","url":"https://feed.craftedsignal.io/briefs/2026-10-checkmk-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Checkmk (\u003c= 1.7.1)","version":"https://jsonfeed.org/version/1.1"}