Vulnerabilities (CVE)

Filtered by vendor Checkmk Subscribe
Filtered by product Checkmk
Total 42 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-31211 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 N/A 6.5 MEDIUM
Insufficient authentication flow in Checkmk before 2.2.0p18, 2.1.0p38 and 2.0.0p39 allows attacker to use locked credentials
CVE-2022-48320 1 Checkmk 1 Checkmk 2024-07-23 N/A 4.3 MEDIUM
Cross-site Request Forgery (CSRF) in Tribe29's Checkmk <= 2.1.0p17, Checkmk <= 2.0.0p31, and all versions of Checkmk 1.6.0 (EOL) allow an attacker to add new visual elements to multiple pages.
CVE-2021-40906 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 4.3 MEDIUM 6.1 MEDIUM
CheckMK Raw Edition software (versions 1.5.0 to 1.6.0) does not sanitise the input of a web service parameter that is in an unauthenticated zone. This Reflected XSS allows an attacker to open a backdoor on the device with HTML content and interpreted by the browser (such as JavaScript or other client-side scripts) or to steal the session cookies of a user who has previously authenticated via a man in the middle. Successful exploitation requires access to the web service resource without authentication.
CVE-2022-24565 1 Checkmk 1 Checkmk 2024-07-23 3.5 LOW 5.4 MEDIUM
Checkmk <=2.0.0p19 Fixed in 2.0.0p20 and Checkmk <=1.6.0p27 Fixed in 1.6.0p28 are affected by a Cross Site Scripting (XSS) vulnerability. The Alias of a site was not properly escaped when shown as condition for notifications.
CVE-2020-28919 1 Checkmk 1 Checkmk 2024-07-23 3.5 LOW 5.4 MEDIUM
A stored cross site scripting (XSS) vulnerability in Checkmk 1.6.0x prior to 1.6.0p19 allows an authenticated remote attacker to inject arbitrary JavaScript via a javascript: URL in a view title.
CVE-2023-0284 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 N/A 8.1 HIGH
Improper Input Validation of LDAP user IDs in Tribe29 Checkmk allows attackers that can control LDAP user IDs to manipulate files on the server. Checkmk <= 2.1.0p19, Checkmk <= 2.0.0p32, and all versions of Checkmk 1.6.0 (EOL) are affected.
CVE-2023-31207 1 Checkmk 1 Checkmk 2024-07-23 N/A 5.5 MEDIUM
Transmission of credentials within query parameters in Checkmk <= 2.1.0p26, <= 2.0.0p35, and <= 2.2.0b6 (beta) may cause the automation user's secret to be written to the site Apache access log.
CVE-2023-23548 1 Checkmk 1 Checkmk 2024-07-23 N/A 6.1 MEDIUM
Reflected XSS in business intelligence in Checkmk <2.2.0p8, <2.1.0p32, <2.0.0p38, <=1.6.0p30.
CVE-2023-1768 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 N/A 5.3 MEDIUM
Inappropriate error handling in Tribe29 Checkmk <= 2.1.0p25, <= 2.0.0p34, <= 2.2.0b3 (beta), and all versions of Checkmk 1.6.0 causes the symmetric encryption of agent data to fail silently and transmit the data in plaintext in certain configurations.
CVE-2022-46836 1 Checkmk 1 Checkmk 2024-07-23 N/A 8.8 HIGH
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable component.
CVE-2022-31258 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 7.2 HIGH 6.7 MEDIUM
In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink.
CVE-2023-31208 2 Checkmk, Tribe29 2 Checkmk, Checkmk 2024-07-23 N/A 8.8 HIGH
Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users.
CVE-2022-4884 1 Checkmk 1 Checkmk 2024-07-23 N/A 4.9 MEDIUM
Path-Traversal in MKP storing in Tribe29 Checkmk <=2.0.0p32 and <= 2.1.0p18 allows an administrator to write mkp files to arbitrary locations via a malicious mkp file.
CVE-2017-14955 1 Checkmk 1 Checkmk 2024-07-23 4.3 MEDIUM 5.9 MEDIUM
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, which allows remote attackers to obtain sensitive user information by reading a GUI crash report.
CVE-2023-6157 1 Checkmk 1 Checkmk 2024-07-23 N/A 8.8 HIGH
Improper neutralization of livestatus command delimiters in ajax_search in Checkmk <= 2.0.0p39, < 2.1.0p37, and < 2.2.0p15 allows arbitrary livestatus command execution for authorized users.
CVE-2023-2020 1 Checkmk 1 Checkmk 2024-07-23 N/A 4.3 MEDIUM
Insufficient permission checks in the REST API in Tribe29 Checkmk <= 2.1.0p27 and <= 2.2.0b4 (beta) allow unauthorized users to schedule downtimes for any host.
CVE-2022-48318 1 Checkmk 1 Checkmk 2024-07-23 N/A 5.3 MEDIUM
No authorisation controls in the RestAPI documentation for Tribe29's Checkmk <= 2.1.0p13 and Checkmk <= 2.0.0p29 which may lead to unintended information disclosure through automatically generated user specific tags within Rest API documentation.
CVE-2022-47909 1 Checkmk 1 Checkmk 2024-07-23 N/A 7.8 HIGH
Livestatus Query Language (LQL) injection in the AuthUser HTTP query header of Tribe29's Checkmk <= 2.1.0p11, Checkmk <= 2.0.0p28, and all versions of Checkmk 1.6.0 (EOL) allows an attacker to perform direct queries to the application's core from localhost.
CVE-2023-22359 1 Checkmk 1 Checkmk 2024-07-23 N/A 4.3 MEDIUM
User enumeration in Checkmk <=2.2.0p4 allows an authenticated attacker to enumerate usernames.
CVE-2022-24564 1 Checkmk 1 Checkmk 2024-07-23 4.3 MEDIUM 6.1 MEDIUM
Checkmk <=2.0.0p19 contains a Cross Site Scripting (XSS) vulnerability. While creating or editing a user attribute, the Help Text is subject to HTML injection, which can be triggered for editing a user.