Branch: refs/heads/2.3.0
Home:
https://github.com/Checkmk/checkmk
Commit: 9baae60a822d26808d558eb1b5ebd46f7c6a2a98
https://github.com/Checkmk/checkmk/commit/9baae60a822d26808d558eb1b5ebd46f7…
Author: Sofia Colakovic <sofia.colakovic(a)checkmk.com>
Date: 2024-02-28 (Wed, 28 Feb 2024)
Changed paths:
A .werks/16173.md
M agents/plugins/symantec_av
A tests/unit-shell/agents/plugins/test_symantec_av.sh
Log Message:
-----------
16173 SEC symantec_av: Don't run sav command if it isn't owned by root
Symantec Anti Virus plugin uses /opt/Symantec/symantec_antivirus/sav command
to monitor a Symantec Anti Virus installation.
To prevent privilege escalation, the plugin (which is run by root user) must
not run executables which can be changed by less privileged users.
In the default installation, sav command is owned by root and root is the only
user with write permissions, which prevents privilege escalation attacks.
With this Werk, the plugin checks if sav command is owned by root and root
is the only user with write permissions before running the command. If that's not
the case the command won't be run. This prevents privilege escalation attacks if
the permissions of the sav command have been changed.
We rate this with a CVSS of 0 (None) (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).
This CVSS is primarily meant to please automatic scanners.
CMK-15318
Change-Id: I677d94136bd21cd54461f6e125764754208d99af
Commit: d1d270d6100c834f283ae744c66bfa10f1502120
https://github.com/Checkmk/checkmk/commit/d1d270d6100c834f283ae744c66bfa10f…
Author: Sofia Colakovic <sofia.colakovic(a)checkmk.com>
Date: 2024-02-28 (Wed, 28 Feb 2024)
Changed paths:
M cmk/base/automations/check_mk.py
M cmk/base/config.py
M cmk/base/core_nagios.py
M cmk/base/sources/_builder.py
M tests/unit/cmk/base/test_server_side_calls.py
Log Message:
-----------
server side calls: remove new ssc macros
For compatibility reasons, it's decided that we don't introduce new
macros for server-side call macros. We support the ones that were
supported in the previous versions.
Change-Id: I623225ed0f0b623528ccb3b482546f84362acd5d
(cherry picked from commit 567f90e8a4d8c24cb94aacfd1aeb12ce588890b9)
Compare:
https://github.com/Checkmk/checkmk/compare/007ae571c77f...d1d270d6100c
To unsubscribe from these emails, change your notification settings at
https://github.com/Checkmk/checkmk/settings/notifications