MEDIUM
SSRF in agent-receiver API
Published Feb 20, 2023
6.8
MEDIUMCVSS 3.1
EPSS 0.28%
Description
Limited Server-Side Request Forgery (SSRF) in agent-receiver in Tribe29's Checkmk <= 2.1.0p11 allows an attacker to communicate with local network restricted endpoints by use of the host registration API.
Affected products
-
Affected
- ≥ 2.1.0, ≤ 2.1.0p11
OR
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
- 2.1.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (3)
- https://checkmk.com/werk/14385 MitigationVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51021 Advisory
- https://www.sonarsource.com/blog/checkmk-rce-chain-1/ ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://checkmk.com/werk/14385 | MitigationVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-51021 | Advisory | |
| https://www.sonarsource.com/blog/checkmk-rce-chain-1/ | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Checkmk
Published Feb 20, 2023
Updated Aug 3, 2024
Reserved Feb 8, 2023
Link CVE-2022-48321
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data