Skip to main content

Vendor/product archive

tribe29 / checkmk CVEs

Beta · best-effort

14 CVEs tagged to tribe29 / checkmk0 Critical, 9 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2023-31209

Published Aug 10, 2023

Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22348

Published May 17, 2023

Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-31208

Published May 17, 2023

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for a…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2023-22294

Published Apr 18, 2023

Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-1768

Published Apr 4, 2023

Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fai…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-22288

Published Mar 20, 2023

HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-0284

Published Jan 26, 2023

Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33912

Published Jun 17, 2022

A permission issue affects users that deployed the shipped version of the Checkmk Debian package. Packages created by the agent bakery (enterprise editions only) were not affected…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-31258

Published May 20, 2022

In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2021-40906

Published Mar 25, 2022

CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an atta…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-40905

Published Mar 25, 2022

The web management console of CheckMK Enterprise Edition (versions 1.5.0 to 2.0.0p9) does not properly sanitise the uploading of ".mkp" files, which are Extension Packages, making…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-14 of 14 CVEsPage 1 of 1