CVE-2021-40904

Publication date 25 March 2022

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

8.8 · High

Score breakdown

Description

The web management console of CheckMK Raw Edition (versions 1.5.0 to 1.6.0) allows a misconfiguration of the web-app Dokuwiki (installed by default), which allows embedded php code. As a result, remote code execution is achieved. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session by a user with the role of administrator.

Read the notes from the security team

Status

Package Ubuntu Release Status
check-mk 22.04 LTS jammy Not in release
20.04 LTS focal Not in release
18.04 LTS bionic Ignored
16.04 LTS xenial Ignored end of standard support, was needed
14.04 LTS trusty Not in release

Notes


0xnishit

Remove dokuwiki: https://github.com/tribe29/checkmk/commit/44e4b1a77d3aeee4bc835d3858fcc1bb00b80072 upstream removed the whole module and therefore we won't be applying a fix

Severity score breakdown

Parameter Value
Base score 8.8 · High
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Access our resources on patching vulnerabilities