[Release] Checkmk stable release 2.1.0p41

Please note that 2.1.0p41 has an issue with Oracle monitoring affecting windows and linux databases.
An exploitable vulnerability was closed leading to a non-functional monitoring of Oracle databases.
We are working on a fix and expect a new version to be released in calendar week 14.

Dear friends of Checkmk,

the new stable release 2.1.0p41 of Checkmk is ready for download.

Changes in all Checkmk Editions:

Checks & agents:

  • 16232 SEC: mk_oracle(ps1): Prevent privilege esclation to root…
  • 16234 SEC: Hide credentials in ps output for mk_oracle…
  • 16198 SEC: mk_informix: Do not allow privilege escalation…

Changes in the Checkmk Enterprise Edition:

NO CHANGES

Changes in the Checkmk Managed Services Edition:

NO CHANGES

You can download Checkmk from our download page: Download Checkmk for free | Checkmk

List of all changes: Werks

We greatly thank you for using Checkmk and wish you a successful monitoring,

Your Checkmk Team

Seems all the werks links are broken and these security fixes aren’t mentioned in the 2.1.0p41 werks?

Security releases follow a special procedure with the relevant werks only becoming visible after the release. They are now all online

All syncing mechanisms are back online and the werks are also available. As @martinh said, security releases are happening pretty silently till everything is in place.

understood, thanks @martinh @Timi !

1 Like

Gotta love automation via Ansible…
After having updated the monitoring (CRE) host i triggered my Ansible playbook and updated all (69) hosts flawlessly with the new agents in just over 6 minutes.

Thursday 21 March 2024  02:51:07 +0100 (0:00:26.300)       0:06:06.035 ********
===============================================================================
Update found plugins with versions from monitoring host ---------------- 55.38s
Gathering Facts -------------------------------------------------------- 41.86s
Install rpm agent via ZYPPER ------------------------------------------- 32.41s
Disable Unwanted CheckMK Services -------------------------------------- 26.30s
Install rpm agent via DNF ---------------------------------------------- 25.73s
Remove rpm agent via ZYPPER -------------------------------------------- 23.90s
Install deb Agent package ---------------------------------------------- 20.95s
Remove rpm agent via DNF ----------------------------------------------- 20.13s
Remove deb Agent package ----------------------------------------------- 17.73s
find installed plugins in main plugins directory ----------------------- 17.59s
Download found rpm agent with version from monitoring host ------------- 17.27s
Create default directories for installing ------------------------------ 14.50s
Cleanup packages directory before installing (if it exists) ------------ 14.12s
Download found deb agent with version from monitoring host -------------- 7.02s
Install rpm agent via YUM ----------------------------------------------- 6.94s
Remove rpm agent via YUM ------------------------------------------------ 5.97s
Set paths of found plugins as fact -------------------------------------- 4.32s
Set fact for rpm agent -------------------------------------------------- 2.79s
Propogate rpm fact to applicable hosts ---------------------------------- 2.32s
Set fact for deb agent -------------------------------------------------- 1.93s
  • Glowsome
4 Likes

Through today’s test of the mk_oracle in 2.1.0p41 and 2.2.0p24 we found that the mk_oracle no longer works. We have opened a ticket for this

Please note that 2.1.0p41 has an issue with Oracle monitoring affecting windows and linux databases.
An exploitable vulnerability was closed leading to a non-functional monitoring of Oracle databases.
We are working on a fix and expect a new version to be released in calendar week 14.

1 Like