CVE-2024-0670
- EPSS 0.12%
- Veröffentlicht 11.03.2024 15:15:47
- Zuletzt bearbeitet 09.12.2024 15:02:35
Privilege escalation in windows agent plugin in Checkmk before 2.2.0p23, 2.1.0p40 and 2.0.0 (EOL) allows local user to escalate privileges
CVE-2023-6740
- EPSS 0.03%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:44:27
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVE-2023-6735
- EPSS 0.07%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:44:26
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVE-2023-31211
- EPSS 0.12%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:01:37
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
CVE-2023-31210
- EPSS 0.12%
- Veröffentlicht 13.12.2023 09:15:34
- Zuletzt bearbeitet 21.11.2024 08:01:37
Usage of user controlled LD_LIBRARY_PATH in agent in Checkmk 2.2.0p10 up to 2.2.0p16 allows malicious Checkmk site user to escalate rights via injection of malicious libraries
CVE-2023-6251
- EPSS 0.19%
- Veröffentlicht 24.11.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:43:27
Cross-site Request Forgery (CSRF) in Checkmk < 2.2.0p15, < 2.1.0p37, <= 2.0.0p39 allow an authenticated attacker to delete user-messages for individual users.
CVE-2023-6157
- EPSS 0.38%
- Veröffentlicht 22.11.2023 17:15:22
- Zuletzt bearbeitet 21.11.2024 08:43:16
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
CVE-2023-6156
- EPSS 0.38%
- Veröffentlicht 22.11.2023 17:15:22
- Zuletzt bearbeitet 21.11.2024 08:43:16
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
CVE-2023-23549
- EPSS 0.05%
- Veröffentlicht 15.11.2023 11:15:08
- Zuletzt bearbeitet 21.11.2024 07:46:23
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.
CVE-2023-31209
- EPSS 0.56%
- Veröffentlicht 10.08.2023 09:15:12
- Zuletzt bearbeitet 21.11.2024 08:01:37
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.