Checkmk Appliance 1.7.21 OpenSSH CVE

CMK version: Appliance 1.7.21

Good morning,

It has been brought to my attention that there are CVEs for OpenSSH (9.2p1) that the appliance uses on 1.7.21. The CVE numbers are 2023-48795, 2023-38408 and 2024-6387.

These CVEs recommend updating to OpenSSH v 10.3.0.

I know that updating OpenSSH individually is not supported or recommended. Will appliance version 1.7.22 resolve these CVEs?

Hi @jlee and thanks for reaching out!

However, the CVEs your scanner found have already been fixed even for the 9.2p1 branch of OpenSSH. You might want to double-check your scanner settings.

Be advised that installing any piece of software on the appliance voids support.

2 Likes