Tribe29 / Checkmk
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-28824 | Privilege escalation in mk_informix plugin | HIGH | 8.8 | Mar 22, 2024 |
| CVE-2023-6740 | Privilege escalation in jar_signature | HIGH | 8.8 | Jan 12, 2024 |
| CVE-2023-6735 | Privilege escalation in mk_tsm | HIGH | 8.8 | Jan 12, 2024 |
| CVE-2023-31211 | Disabled automation users could still authenticate | HIGH | 8.8 | Jan 12, 2024 |
| CVE-2023-31209 | Command injection via active checks and REST API | HIGH | 8.8 | Aug 10, 2023 |
| CVE-2023-22359 | User-enumeration in RestAPI | MEDIUM | 4.3 | Jun 26, 2023 |
| CVE-2023-22348 | Reading host_configs does not honour contact groups | MEDIUM | 4.3 | May 17, 2023 |
| CVE-2023-31208 | Livestatus command injection in RestAPI | HIGH | 8.8 | May 17, 2023 |
| CVE-2023-31207 | Automation user secret logged to Apache access log | MEDIUM | 5.5 | May 2, 2023 |
| CVE-2022-46302 | Remote Code Execution with Root Privileges via Broad Apache Permissions | HIGH | 8.8 | Apr 20, 2023 |
| CVE-2023-22294 | Privilege escalation in Checkmk Appliance | HIGH | 8.8 | Apr 18, 2023 |
| CVE-2023-2020 | Unauthorized scheduling of downtimes via REST API | MEDIUM | 4.3 | Apr 18, 2023 |
| CVE-2023-1768 | Symmetric agent data encryption fails silently | MEDIUM | 5.3 | Apr 4, 2023 |
| CVE-2023-22288 | Email HTML Injection | MEDIUM | 6.8 | Mar 20, 2023 |
| CVE-2022-48320 | CSRF in add-visual endpoint | MEDIUM | 5.4 | Feb 20, 2023 |
| CVE-2022-48319 | Host secret disclosed in Checkmk logs | MEDIUM | 6.5 | Feb 20, 2023 |
| CVE-2022-48318 | Insecure access control mechanisms for RestAPI documentation | MEDIUM | 5.3 | Feb 20, 2023 |
| CVE-2022-48317 | Insecure Termination of RestAPI Session Tokens | CRITICAL | 9.8 | Feb 20, 2023 |
| CVE-2022-48321 | SSRF in agent-receiver API | MEDIUM | 6.8 | Feb 20, 2023 |
| CVE-2022-47909 | LQL Injection in Livestatus HTTP headers | HIGH | 7.8 | Feb 20, 2023 |
| CVE-2022-46836 | PHP code injection in watolib | CRITICAL | 9.1 | Feb 20, 2023 |
| CVE-2022-46303 | Command injection in SMS notifications | HIGH | 8.0 | Feb 20, 2023 |
| CVE-2022-43440 | Privilege escalation via manipulated unixcat executable | HIGH | 8.8 | Feb 9, 2023 |
| CVE-2023-0284 | Improper validation of LDAP user IDs | HIGH | 8.1 | Jan 24, 2023 |
| CVE-2022-4884 | Path-Traversal in MKP storing | MEDIUM | 4.9 | Jan 9, 2023 |
Showing 1 to 17 of 17 CVEs