Vulnerabilities
Vulnerable Software
Tribe29:  >> Checkmk  >> 1.6.0b10  Security Vulnerabilities
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
CVSS Score
8.8
EPSS Score
0.001
Published
2024-01-12
Privilege escalation in mk_tsm agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVSS Score
8.8
EPSS Score
0.0
Published
2024-01-12
Privilege escalation in jar_signature agent plugin in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows local user to escalate privileges
CVSS Score
8.8
EPSS Score
0.0
Published
2024-01-12
Improper neutralization of active check command arguments in Checkmk < 2.1.0p32, < 2.0.0p38, < 2.2.0p4 leads to arbitrary command execution for authenticated users.
CVSS Score
8.8
EPSS Score
0.006
Published
2023-08-10
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
CVSS Score
4.3
EPSS Score
0.002
Published
2023-05-17
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVSS Score
8.3
EPSS Score
0.005
Published
2023-05-17
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
CVSS Score
8.8
EPSS Score
0.002
Published
2023-04-18
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
CVSS Score
3.7
EPSS Score
0.002
Published
2023-04-04
HTML Email Injection in Tribe29 Checkmk <=2.1.0p23; <=2.0.0p34, and all versions of Checkmk 1.6.0 allows an authenticated attacker to inject malicious HTML into Emails
CVSS Score
4.1
EPSS Score
0.005
Published
2023-03-20
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.
CVSS Score
6.8
EPSS Score
0.005
Published
2023-01-26


Contact Us

Shodan ® - All rights reserved