CVE-2023-23548
- EPSS 0.44%
- Veröffentlicht 01.08.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:46:23
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
CVE-2023-22359
- EPSS 0.26%
- Veröffentlicht 26.06.2023 07:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:37
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
CVE-2023-22348
- EPSS 0.19%
- Veröffentlicht 17.05.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:36
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
CVE-2023-31208
- EPSS 0.68%
- Veröffentlicht 17.05.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:37
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVE-2023-31207
- EPSS 0.06%
- Veröffentlicht 02.05.2023 09:15:10
- Zuletzt bearbeitet 30.01.2025 15:15:15
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
CVE-2022-46302
- EPSS 1.16%
- Veröffentlicht 20.04.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:30:20
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allow...
CVE-2023-2020
- EPSS 0.14%
- Veröffentlicht 18.04.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 07:57:46
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
CVE-2023-1768
- EPSS 0.22%
- Veröffentlicht 04.04.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 07:39:52
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations...
CVE-2023-22288
- EPSS 0.65%
- Veröffentlicht 20.03.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:44:27
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
CVE-2022-48321
- EPSS 0.1%
- Veröffentlicht 20.02.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:33:09
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.