CVE-2023-31208
- EPSS 0.97%
- Veröffentlicht 17.05.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:37
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVE-2023-31207
- EPSS 0.22%
- Veröffentlicht 02.05.2023 09:15:10
- Zuletzt bearbeitet 30.01.2025 15:15:15
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
CVE-2022-46302
- EPSS 0.39%
- Veröffentlicht 20.04.2023 14:15:08
- Zuletzt bearbeitet 21.11.2024 07:30:20
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allow...
CVE-2023-2020
- EPSS 0.4%
- Veröffentlicht 18.04.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 07:57:46
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
CVE-2023-1768
- EPSS 0.91%
- Veröffentlicht 04.04.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 07:39:52
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations...
CVE-2023-22288
- EPSS 0.4%
- Veröffentlicht 20.03.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:44:27
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
CVE-2022-46303
- EPSS 1.14%
- Veröffentlicht 20.02.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:30:20
Command injection in SMS notifications in Tribe29 Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker with User Management permissions, as well as LDAP administrators in certain scenarios, to perform arbitrary command...
CVE-2022-46836
- EPSS 1.13%
- Veröffentlicht 20.02.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:31:08
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.
CVE-2022-47909
- EPSS 0.39%
- Veröffentlicht 20.02.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:32:31
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from loc...
CVE-2022-48317
- EPSS 0.46%
- Veröffentlicht 20.02.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 07:33:08
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.