Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.
References
History

Tue, 13 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 11:00:00 +0000

Type Values Removed Values Added
Description Privilege escalation in jar_signature agent plugin in Checkmk versions <2.4.0b7 (beta), <2.3.0p32, <2.2.0p42, and 2.1.0p49 (EOL) allow user with write access to JAVA_HOME/bin directory to escalate privileges.
Title Privilege escalation in jar_signature
Weaknesses CWE-427
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Checkmk

Published: 2025-05-13T10:45:31.406Z

Updated: 2025-05-13T13:05:57.675Z

Reserved: 2025-04-14T09:52:19.273Z

Link: CVE-2025-32917

cve-icon Vulnrichment

Updated: 2025-05-13T13:05:48.196Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T11:15:47.570

Modified: 2025-05-13T19:35:18.080

Link: CVE-2025-32917

cve-icon Redhat

No data.