Vulnerability Details CVE-2022-47909
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 51.3%
CVSS Severity
CVSS v3 Score 6.8
Products affected by CVE-2022-47909
-
cpe:2.3:a:checkmk:checkmk:1.6.0
-
cpe:2.3:a:checkmk:checkmk:2.0.0
-
cpe:2.3:a:checkmk:checkmk:2.1.0