CVE-2025-64998
EUVD-2025-20895824.03.2026, 12:16
Exposure of session signing secret in Checkmk <2.4.0p23, <2.3.0p45 and 2.2.0 allows an administrator of a remote site with config sync enabled to hijack sessions on the central site by forging session cookies.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| checkmk | checkmk | 2.4.0 ≤ 𝑥 ≤ 2.4.0p22 |
| checkmk | checkmk | 2.3.0 ≤ 𝑥 ≤ 2.3.0p44 |
| checkmk | checkmk | 2.2.0 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References