Page 2 of 16 results (0.005 seconds)

CVSS: 4.3EPSS: 0%CPEs: 45EXPL: 0

Improper Authorization in RestAPI in Checkmk GmbH's Checkmk versions <2.1.0p28 and <2.2.0b8 allows remote authenticated users to read arbitrary host_configs. • https://checkmk.com/werk/13982 • CWE-285: Improper Authorization •

CVSS: 8.8EPSS: 0%CPEs: 90EXPL: 0

Improper neutralization of livestatus command delimiters in the RestAPI in Checkmk < 2.0.0p36, < 2.1.0p28, and < 2.2.0b8 (beta) allows arbitrary livestatus command execution for authorized users. • https://checkmk.com/werk/15191 • CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') CWE-140: Improper Neutralization of Delimiters •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

Privilege escalation in Tribe29 Checkmk Appliance before 1.6.4 allows authenticated site users to escalate privileges via incorrectly set permissions. • https://checkmk.com/werk/9520 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVSS: 8.8EPSS: 0%CPEs: 86EXPL: 0

Uncontrolled Search Path Element in Checkmk Agent in Tribe29 Checkmk before 2.1.0p1, before 2.0.0p25 and before 1.6.0p29 on a Checkmk server allows the site user to escalate privileges via a manipulated unixcat executable • https://checkmk.com/werk/14087 • CWE-427: Uncontrolled Search Path Element •

CVSS: 8.2EPSS: 0%CPEs: 88EXPL: 0

In Checkmk before 1.6.0p29, 2.x before 2.0.0p25, and 2.1.x before 2.1.0b10, a site user can escalate to root by editing an OMD hook symlink. En Checkmk versiones anteriores a 1.6.0p29, 2.x anteriores a 2.0.0p25, y 2.1.x anteriores a 2.1.0b10, un usuario del sitio puede escalar a root editando un enlace simbólico del hook OMD • https://checkmk.com/werk/13902 https://forum.checkmk.com/c/announcements/18 • CWE-59: Improper Link Resolution Before File Access ('Link Following') •