Show filters
42 Total Results
Displaying 31-40 of 42
Sort by:
Attacker Value
Unknown

CVE-2023-6157

Disclosure Date: November 22, 2023 (last updated July 24, 2024)
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
Attacker Value
Unknown

CVE-2023-6156

Disclosure Date: November 22, 2023 (last updated July 24, 2024)
Improper neutralization of livestatus command delimiters in the availability timeline in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
Attacker Value
Unknown

CVE-2023-23549

Disclosure Date: November 15, 2023 (last updated July 24, 2024)
Improper Input Validation in Checkmk <2.2.0p15, <2.1.0p37, <=2.0.0p39 allows priviledged attackers to cause partial denial of service of the UI via too long hostnames.
Attacker Value
Unknown

CVE-2023-31209

Disclosure Date: August 10, 2023 (last updated July 24, 2024)
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
Attacker Value
Unknown

CVE-2023-23548

Disclosure Date: August 01, 2023 (last updated July 24, 2024)
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
Attacker Value
Unknown

CVE-2023-22359

Disclosure Date: June 26, 2023 (last updated July 24, 2024)
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
Attacker Value
Unknown

CVE-2023-22348

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
Attacker Value
Unknown

CVE-2023-31208

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
Attacker Value
Unknown

CVE-2023-31207

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
Attacker Value
Unknown

CVE-2023-2020

Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.