Branch: refs/heads/1.6.0
Home:
https://github.com/tribe29/checkmk
Commit: ed638f627c28d713ca1fd2671fc6c2f442b89d5a
https://github.com/tribe29/checkmk/commit/ed638f627c28d713ca1fd2671fc6c2f44…
Author: Sergey Kipnis <sergey.kipnis(a)tribe29.com>
Date: 2020-08-25 (Tue, 25 Aug 2020)
Changed paths:
M agents/wnx/src/common/wtools.cpp
M agents/wnx/src/common/wtools.h
M agents/wnx/src/engine/cfg.cpp
M agents/wnx/src/engine/cfg_details.h
M agents/wnx/watest/test-yaml.cpp
Log Message:
-----------
[FEED-5122] - remove write access to ProgramData\checkmk\agent directory from Users
group
Fix prevents possibility to hack OS by creating/modifying files which controls behavior of
the Windows Agent Service.
Change-Id: If3eeeeb729e00f6124ae5010eb967896f486067f
Commit: d97761beda3a71be0b499e75c6b05aa35cf08d99
https://github.com/tribe29/checkmk/commit/d97761beda3a71be0b499e75c6b05aa35…
Author: Sergey Kipnis <sergey.kipnis(a)tribe29.com>
Date: 2020-08-26 (Wed, 26 Aug 2020)
Changed paths:
A .werks/11460
Log Message:
-----------
11460 SECURITY Windows agent service sets correct access rights in ProgramData
directory
Previously, a standard user can write in ProgramData/checkmk/agent directory,
thereby getting a possibility to modify sensitive information.
With this fix the above mentioned vulnerability is eliminated: a standard user
has a right to read and execute.
Change-Id: Ib806ad2fb717cc0ef11246576a953ff1d179a0e9
Compare:
https://github.com/tribe29/checkmk/compare/070baf7a7f8e...d97761beda3a