Checkmk
Top 1M siteProgram Details
Checkmk's disclosure programme covers its monitoring codebase, appliance, Kubernetes cluster collector, Grafana datasource and websites. Reports go to [email protected] in English or German with a description and proof of concept, and the security team replies within a few business days. Anonymous submissions are welcome and reporters can be credited by name. Checkmk aims to address reported issues within 90 days; there is no committed bounty, only a possible token of appreciation.
- Allows Disclosure
- Yes
- Disclosure Window
- 90 days
Rules & Testing
Excluded Methods
Scope (6 targets)
- Checkmk codebase other
- Checkmk K8s cluster collector other
- Checkmk Grafana datasource other
- Checkmk appliance hardware
- checkmk.com website and its subdomains web
- tribe29.com website and its subdomains web
Out of Scope
Self-XSS that cannot be exploited against other users, (Distributed) Denial of service attacks against the in-scope domains, machines running Checkmk, or the Checkmk appliances, Lack of HSTS enforcement for Checkmk web applications, Missing cookie flags without a PoC on how this can be exploited, Missing security headers without a PoC on how this can be exploited, HTTP request smuggling without any proven business impact, Blind SSRF without proven business impact (DNS pingback only is not sufficient), HTTP Host header manipulation without a proven business impact, Disclosed and/or misconfigured API keys without proven business impact, Verbose error and log messages that do not reveal personal data or secrets, Clickjacking attacks with low or no impact, Version disclosure without a PoC on how it can be exploited, Open ports without a PoC on how it can be exploited, Weak SSL configurations and SSL/TLS scan reports, Arbitrary file upload without proof of the existence of the uploaded file, Best practices violations (password complexity, expiration, re-use) with low or no impact, Installation of malicious software on machines running Checkmk or on the Checkmk appliances, Physical attacks against the Checkmk appliances, Social engineering attacks against Checkmk employees, partners, or customers, Anything related to email spoofing, SPF, DMARC or DKIM, Email bombing, Side-channel attacks
Security
- PGP Key
- https://checkmk.com/.well-known/pgp-key.txt
- Preferred Languages
- English, German
security.txt
- Contact
- mailto:[email protected]
- Encryption
- https://checkmk.com/.well-known/pgp-key.txt
- Policy
- https://checkmk.com/responsible-disclosure-policy
- Expires
- Sep 20, 2028