4.3

CVE-2023-22359

User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckmkCheckmk Version2.2.0 Update-
CheckmkCheckmk Version2.2.0 Updateb1
CheckmkCheckmk Version2.2.0 Updateb2
CheckmkCheckmk Version2.2.0 Updateb3
CheckmkCheckmk Version2.2.0 Updateb4
CheckmkCheckmk Version2.2.0 Updateb5
CheckmkCheckmk Version2.2.0 Updateb6
CheckmkCheckmk Version2.2.0 Updateb7
CheckmkCheckmk Version2.2.0 Updateb8
CheckmkCheckmk Version2.2.0 Updatei1
CheckmkCheckmk Version2.2.0 Updatep1
CheckmkCheckmk Version2.2.0 Updatep2
CheckmkCheckmk Version2.2.0 Updatep3
CheckmkCheckmk Version2.2.0 Updatep4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.495
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
security@checkmk.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.