{"id":"CVE-2021-40905","details":"The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of \".mkp\" files, which are Extension Packages, making remote code execution possible. Successful exploitation requires access to the web management interface, either with valid credentials or with a hijacked session of a user with administrator role. NOTE: the vendor states that this is the intended behavior: admins are supposed to be able to execute code in this manner.","modified":"2026-07-10T04:00:52.623993529Z","published":"2022-03-25T23:15:08.237Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"tribe29:checkmk","cpes":["cpe:2.3:a:tribe29:checkmk:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.5.0"},{"fixed":"2.0.0"}]}]},"references":[{"type":"WEB","url":"https://docs.checkmk.com/latest/en/mkps.html"},{"type":"EVIDENCE","url":"https://github.com/Edgarloyola/CVE-2021-40905"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/checkmk/checkmk","events":[{"introduced":"a08e390df0ae711bbee6fbdd0d32da1452918ae3"},{"last_affected":"966a84e7fae45f25cc63150a256dc4df3907c9b0"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:checkmk:checkmk:2.0.0:-:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:i1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p1:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p2:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p3:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p4:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p5:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p6:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p7:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:b8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p8:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p10:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p11:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p12:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p13:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p14:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p15:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p16:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p17:*:*:*:*:*:*","cpe:2.3:a:checkmk:checkmk:2.0.0:p9:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.0.0-NA"},{"last_affected":"2.0.0-NA"},{"introduced":"2.0.0-b1"},{"last_affected":"2.0.0-b1"},{"introduced":"2.0.0-i1"},{"last_affected":"2.0.0-i1"},{"introduced":"2.0.0-p1"},{"last_affected":"2.0.0-p1"},{"introduced":"2.0.0-b2"},{"last_affected":"2.0.0-b2"},{"introduced":"2.0.0-p2"},{"last_affected":"2.0.0-p2"},{"introduced":"2.0.0-b3"},{"last_affected":"2.0.0-b3"},{"introduced":"2.0.0-p3"},{"last_affected":"2.0.0-p3"},{"introduced":"2.0.0-b4"},{"last_affected":"2.0.0-b4"},{"introduced":"2.0.0-p4"},{"last_affected":"2.0.0-p4"},{"introduced":"2.0.0-b5"},{"last_affected":"2.0.0-b5"},{"introduced":"2.0.0-p5"},{"last_affected":"2.0.0-p5"},{"introduced":"2.0.0-b6"},{"last_affected":"2.0.0-b6"},{"introduced":"2.0.0-p6"},{"last_affected":"2.0.0-p6"},{"introduced":"2.0.0-b7"},{"last_affected":"2.0.0-b7"},{"introduced":"2.0.0-p7"},{"last_affected":"2.0.0-p7"},{"introduced":"2.0.0-b8"},{"last_affected":"2.0.0-b8"},{"introduced":"2.0.0-p8"},{"last_affected":"2.0.0-p8"},{"introduced":"2.0.0-p10"},{"last_affected":"2.0.0-p10"},{"introduced":"2.0.0-p11"},{"last_affected":"2.0.0-p11"},{"introduced":"2.0.0-p12"},{"last_affected":"2.0.0-p12"},{"introduced":"2.0.0-p13"},{"last_affected":"2.0.0-p13"},{"introduced":"2.0.0-p14"},{"last_affected":"2.0.0-p14"},{"introduced":"2.0.0-p15"},{"last_affected":"2.0.0-p15"},{"introduced":"2.0.0-p16"},{"last_affected":"2.0.0-p16"},{"introduced":"2.0.0-p17"},{"last_affected":"2.0.0-p17"},{"introduced":"2.0.0-p9"},{"last_affected":"2.0.0-p9"}]}}],"versions":["2.0.0-NA","2.0.0-b1","2.0.0-b2","2.0.0-b3","2.0.0-b4","2.0.0-b5","2.0.0-b6","2.0.0-b7","2.0.0-b8","2.0.0-p10","2.0.0-p11","2.0.0-p12","2.0.0-p13","2.0.0-p14","2.0.0-p15","2.0.0-p16","2.0.0-p17","2.0.0-p9","v2.0.0p9","v2.0.0p8","v2.0.0p7","v2.0.0p6","v2.0.0p5","v2.0.0p4","v2.0.0p3","v2.0.0p1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-40905.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}