Vulnerabilities > Tribe29 > Checkmk

DATE CVE VULNERABILITY TITLE RISK
2023-02-20 CVE-2022-47909 Unspecified vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.
local
low complexity
tribe29
7.8
2023-02-20 CVE-2022-48317 Insufficient Session Expiration vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Expired sessions were not securely terminated in the RestAPI for Tribe29's Checkmk <= 2.1.0p10 and Checkmk <= 2.0.0p28 allowing an attacker to use expired session tokens when communicating with the RestAPI.
network
low complexity
tribe29 CWE-613
critical
9.8
2023-02-20 CVE-2022-48318 Missing Authorization vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.
network
low complexity
tribe29 CWE-862
5.3
2023-02-20 CVE-2022-48319 Information Exposure Through Log Files vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Sensitive host secret disclosed in cmk-update-agent.log file in Tribe29's Checkmk <= 2.1.0p13, Checkmk <= 2.0.0p29, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to gain access to the host secret through the unprotected agent updater log file.
local
low complexity
tribe29 CWE-532
5.5
2023-02-20 CVE-2022-48320 Cross-Site Request Forgery (CSRF) vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
network
low complexity
tribe29 CWE-352
4.3
2023-02-20 CVE-2022-48321 Server-Side Request Forgery (SSRF) vulnerability in Tribe29 Checkmk 2.1.0
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
local
low complexity
tribe29 CWE-918
3.3
2023-02-09 CVE-2022-43440 Uncontrolled Search Path Element vulnerability in Tribe29 Checkmk
Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows the site user to escalate privileges via a manipulated unixcat executable
local
low complexity
tribe29 CWE-427
7.8
2023-01-26 CVE-2023-0284 Improper Input Validation vulnerability in Tribe29 Checkmk
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server.
network
low complexity
tribe29 CWE-20
8.1
2023-01-09 CVE-2022-4884 Path Traversal vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.
network
low complexity
tribe29 CWE-22
4.9
2022-06-17 CVE-2022-33912 Incorrect Default Permissions vulnerability in Tribe29 Checkmk
A permission issue affects users that deployed the shipped version of the Checkmk Debian package.
local
low complexity
tribe29 CWE-276
7.2