Vulnerabilities > Checkmk

DATE CVE VULNERABILITY TITLE RISK
2023-02-20 CVE-2022-48317 Insufficient Session Expiration vulnerability in Checkmk 2.0.0/2.1.0
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.
network
low complexity
checkmk CWE-613
critical
9.8
2023-02-20 CVE-2022-48318 Missing Authorization vulnerability in Checkmk 2.0.0/2.1.0
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.
network
low complexity
checkmk CWE-862
5.3
2023-02-20 CVE-2022-48319 Information Exposure Through Log Files vulnerability in Checkmk 2.0.0/2.1.0
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
local
low complexity
checkmk CWE-532
5.5
2023-02-20 CVE-2022-48320 Cross-Site Request Forgery (CSRF) vulnerability in Checkmk 2.0.0/2.1.0
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
network
low complexity
checkmk CWE-352
4.3
2023-02-20 CVE-2022-48321 Server-Side Request Forgery (SSRF) vulnerability in Checkmk 2.1.0
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
local
low complexity
checkmk CWE-918
3.3
2023-02-09 CVE-2022-43440 Uncontrolled Search Path Element vulnerability in Checkmk
Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows the site user to escalate privileges via a manipulated unixcat executable
local
low complexity
checkmk CWE-427
7.8
2023-01-26 CVE-2023-0284 Improper Input Validation vulnerability in multiple products
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server.
network
low complexity
tribe29 checkmk CWE-20
8.1
2023-01-09 CVE-2022-4884 Path Traversal vulnerability in Checkmk 2.0.0/2.1.0
Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.
network
low complexity
checkmk CWE-22
4.9
2022-06-17 CVE-2022-33912 Incorrect Default Permissions vulnerability in multiple products
A permission issue affects users that deployed the shipped version of the Checkmk Debian package.
local
low complexity
tribe29 checkmk CWE-276
7.8
2022-05-20 CVE-2022-31258 Link Following vulnerability in multiple products
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.
local
low complexity
tribe29 checkmk CWE-59
6.7