Vulnerabilities > CVE-2022-47909 - Unspecified vulnerability in Checkmk 2.0.0/2.1.0
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 102 |