CVE-2023-31211
- EPSS 0.12%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:01:37
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
CVE-2023-6735
- EPSS 0.07%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:44:26
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVE-2023-6740
- EPSS 0.03%
- Veröffentlicht 12.01.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 08:44:27
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVE-2023-31209
- EPSS 0.56%
- Veröffentlicht 10.08.2023 09:15:12
- Zuletzt bearbeitet 21.11.2024 08:01:37
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
CVE-2023-22348
- EPSS 0.15%
- Veröffentlicht 17.05.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 07:44:36
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
CVE-2023-31208
- EPSS 0.51%
- Veröffentlicht 17.05.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:01:37
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVE-2023-22294
- EPSS 0.23%
- Veröffentlicht 18.04.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 07:44:28
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
CVE-2023-1768
- EPSS 0.16%
- Veröffentlicht 04.04.2023 07:15:11
- Zuletzt bearbeitet 21.11.2024 07:39:52
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations...
CVE-2023-22288
- EPSS 0.64%
- Veröffentlicht 20.03.2023 16:15:13
- Zuletzt bearbeitet 21.11.2024 07:44:27
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
CVE-2023-0284
- EPSS 0.53%
- Veröffentlicht 26.01.2023 21:18:07
- Zuletzt bearbeitet 21.11.2024 07:36:53
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.