Vulnerabilities > Tribe29

DATE CVE VULNERABILITY TITLE RISK
2023-08-01 CVE-2023-23548 Cross-site Scripting vulnerability in Tribe29 Checkmk
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
network
low complexity
tribe29 CWE-79
6.1
2023-06-26 CVE-2023-22359 Unspecified vulnerability in Tribe29 Checkmk 2.2.0
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
network
low complexity
tribe29
4.3
2023-05-17 CVE-2023-22348 Unspecified vulnerability in Tribe29 Checkmk
Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs.
network
low complexity
tribe29
4.3
2023-05-17 CVE-2023-31208 Command Injection vulnerability in Tribe29 Checkmk
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
network
low complexity
tribe29 CWE-77
8.8
2023-05-15 CVE-2023-22318 Improper Locking vulnerability in Tribe29 Checkmk Appliance Firmware
Denial of service in Webconf in Tribe29 Checkmk Appliance before 1.6.5.
network
low complexity
tribe29 CWE-667
7.5
2023-05-02 CVE-2023-31207 Information Exposure Through Log Files vulnerability in Tribe29 Checkmk 2.0.0/2.1.0
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
local
low complexity
tribe29 CWE-532
5.5
2023-04-20 CVE-2022-46302 Inclusion of Functionality from Untrusted Control Sphere vulnerability in Tribe29 Checkmk 1.6.0/2.0.0
Broad access controls could allow site users to directly interact with the system Apache installation when providing the reverse proxy configurations for Tribe29's Checkmk <= 2.1.0p6, Checkmk <= 2.0.0p27, and all versions of Checkmk 1.6.0 (EOL) allowing an attacker to perform remote code execution with root privileges on the underlying host.
local
low complexity
tribe29 CWE-829
8.8
2023-04-20 CVE-2023-22309 Cross-site Scripting vulnerability in Tribe29 Checkmk Appliance Firmware
Reflective Cross-Site-Scripting in Webconf in Tribe29 Checkmk Appliance before 1.6.4.
network
low complexity
tribe29 CWE-79
6.1
2023-04-18 CVE-2023-22294 Incorrect Permission Assignment for Critical Resource vulnerability in Tribe29 Checkmk
Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions.
network
low complexity
tribe29 CWE-732
8.8
2023-04-18 CVE-2023-22307 Exposure of Resource to Wrong Sphere vulnerability in Tribe29 Checkmk Appliance Firmware
Sensitive data exposure in Webconf in Tribe29 Checkmk Appliance before 1.6.4 allows local attacker to retrieve passwords via reading log files.
local
low complexity
tribe29 CWE-668
5.5