Show filters
51 Total Results
Displaying 31-40 of 51
Sort by:
Attacker Value
Unknown
CVE-2023-23548
Disclosure Date: August 01, 2023 (last updated July 24, 2024)
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
0
Attacker Value
Unknown
CVE-2023-22348
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
0
Attacker Value
Unknown
CVE-2023-31208
Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
0
Attacker Value
Unknown
CVE-2023-31207
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
0
Attacker Value
Unknown
CVE-2022-46302
Disclosure Date: April 20, 2023 (last updated February 24, 2025)
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.
0
Attacker Value
Unknown
CVE-2023-2020
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
0
Attacker Value
Unknown
CVE-2023-1768
Disclosure Date: April 04, 2023 (last updated February 24, 2025)
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
0
Attacker Value
Unknown
CVE-2023-22288
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
0
Attacker Value
Unknown
CVE-2022-48321
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
0
Attacker Value
Unknown
CVE-2022-48320
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
0