Show filters
77 Total Results
Displaying 51-60 of 77
Sort by:
Attacker Value
Unknown
CVE-2023-22294
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
0
Attacker Value
Unknown
CVE-2023-2020
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
0
Attacker Value
Unknown
CVE-2023-1768
Disclosure Date: April 04, 2023 (last updated February 24, 2025)
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
0
Attacker Value
Unknown
CVE-2023-22288
Disclosure Date: March 20, 2023 (last updated February 24, 2025)
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
0
Attacker Value
Unknown
CVE-2022-48321
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
0
Attacker Value
Unknown
CVE-2022-48320
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
0
Attacker Value
Unknown
CVE-2022-48319
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
0
Attacker Value
Unknown
CVE-2022-48318
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.
0
Attacker Value
Unknown
CVE-2022-48317
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.
0
Attacker Value
Unknown
CVE-2022-47909
Disclosure Date: February 20, 2023 (last updated February 24, 2025)
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.
0