7.8

CVE-2023-31210

Privilege escalation in agent via LD_LIBRARY_PATH

Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Checkmk ≫ Checkmk Version 2.2.0 Update p10
Checkmk ≫ Checkmk Version 2.2.0 Update p11
Checkmk ≫ Checkmk Version 2.2.0 Update p12
Checkmk ≫ Checkmk Version 2.2.0 Update p13
Checkmk ≫ Checkmk Version 2.2.0 Update p14
Checkmk ≫ Checkmk Version 2.2.0 Update p15
Checkmk ≫ Checkmk Version 2.2.0 Update p16
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.54% 0.409
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
security@checkmk.com 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.