8.8

CVE-2023-31210

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CheckmkCheckmk Version2.2.0 Updatep10
CheckmkCheckmk Version2.2.0 Updatep11
CheckmkCheckmk Version2.2.0 Updatep12
CheckmkCheckmk Version2.2.0 Updatep13
CheckmkCheckmk Version2.2.0 Updatep14
CheckmkCheckmk Version2.2.0 Updatep15
CheckmkCheckmk Version2.2.0 Updatep16
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.321
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@checkmk.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.