Back to Database
Status published
Medium
CVE-2024-47094
Logging of sitesecret to automations log
Vulnerability Description
Insertion of Sensitive Information into Log File in Checkmk GmbH's Checkmk versions <2.3.0p22, <2.2.0p37, <2.1.0p50 (EOL) causes remote site secrets to be written to web log files accessible to local site users.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47094
Credits & Attribution
No credits recorded in the NVD database.
References
More from Checkmk GmbH
View All →CVE-2025-65000
Exposure of SSH Private Keys in Remote Alert Handlers (Linux) Rule
Low
2.3
CVE-2025-64999
Cross-site scripting in HTML logs of Synthetic Monitoring test services
High
7.3
CVE-2025-64998
Session hijacking via exposed session signing secret in distributed Checkmk setups
High
7.3
CVE-2025-64997
Insufficient permission validation when showing agent information
Medium
6.3
CVE-2025-64996
Overly broad file permissions in the mk_inotify plugin allows reading and manipulating the plugin's output
Medium
4.8
Affected Vendor
Checkmk GmbH
View all reports →Affected Software
Checkmk
Vulnerable Versions:
2.3.0, 2.2.0, 2.1.0
Timeline
Official Publish:
November 29th, 2024
Last Modified:
September 11th, 2025
Added to House:
July 22nd, 2026